Unchecked return value in ModSecurity - CVE-2025-54571
Published: August 6, 2025
Vulnerability identifier: #VU113672
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-54571
CWE-ID: CWE-252
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient checks of the return value when handling HTTP requests. A remote attacker can override HTTP response Content-Type header and perform XSS attacks or disclose arbitrary script source code.
Affected software
ModSecurity
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Server Applications Module
openSUSE Leap
openEuler
EasyApache
Infrastructure Technology
Oracle HTTP Server
Communications Unified Assurance
apache2-mod_security2
apache2-mod_security2-debugsource
apache2-mod_security2-debuginfo
mod_security-debugsource
mod_security-debuginfo
mod_security
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
Server Applications Module
openSUSE Leap
openEuler
EasyApache
Infrastructure Technology
Oracle HTTP Server
Communications Unified Assurance
apache2-mod_security2
apache2-mod_security2-debugsource
apache2-mod_security2-debuginfo
mod_security-debugsource
mod_security-debuginfo
mod_security
How to mitigate CVE-2025-54571
Install updates from vendor's website.
ModSecurity - update to 2.9.12
EasyApache - update to 4 25-26
apache2-mod_security2 - addressed in versions 2.8.0-7.12.1, 2.9.4-150400.3.12.1
apache2-mod_security2-debugsource - addressed in versions 2.8.0-7.12.1, 2.9.4-150400.3.12.1
apache2-mod_security2-debuginfo - addressed in versions 2.8.0-7.12.1, 2.9.4-150400.3.12.1
mod_security-debugsource - update to 2.9.12-1
mod_security-debuginfo - update to 2.9.12-1
mod_security - update to 2.9.12-1
EasyApache - update to 4 25-26
apache2-mod_security2 - addressed in versions 2.8.0-7.12.1, 2.9.4-150400.3.12.1
apache2-mod_security2-debugsource - addressed in versions 2.8.0-7.12.1, 2.9.4-150400.3.12.1
apache2-mod_security2-debuginfo - addressed in versions 2.8.0-7.12.1, 2.9.4-150400.3.12.1
mod_security-debugsource - update to 2.9.12-1
mod_security-debuginfo - update to 2.9.12-1
mod_security - update to 2.9.12-1
External References
Related Security Bulletins
- XSS and information disclosure in ModSecurity
- openEuler 22.03 LTS SP4 update for mod_security
- openEuler 22.03 LTS SP3 update for mod_security
- openEuler 24.03 LTS SP2 update for mod_security
- openEuler 22.03 LTS SP4 update for mod_security
- openEuler 24.03 LTS SP1 update for mod_security
- openEuler 22.03 LTS SP4 update for mod_security
- openEuler 22.03 LTS SP4 update for mod_security
- openEuler 24.03 LTS update for mod_security
- openEuler 22.03 LTS SP3 update for mod_security
- openEuler 22.03 LTS SP3 update for mod_security
- openEuler 22.03 LTS SP3 update for mod_security
- openEuler 24.03 LTS SP2 update for mod_security
- openEuler 24.03 LTS SP2 update for mod_security
- openEuler 24.03 LTS SP1 update for mod_security
- openEuler 22.03 LTS SP4 update for mod_security
- openEuler 24.03 LTS SP2 update for mod_security
- openEuler 22.03 LTS SP3 update for mod_security
- openEuler 24.03 LTS SP1 update for mod_security
- openEuler 24.03 LTS update for mod_security
- openEuler 24.03 LTS SP2 update for mod_security
- openEuler 24.03 LTS SP1 update for mod_security
- openEuler 24.03 LTS update for mod_security
- openEuler 24.03 LTS update for mod_security
- openEuler 24.03 LTS SP1 update for mod_security
- openEuler 24.03 LTS update for mod_security
- openEuler 22.03 LTS SP4 update for mod_security
- openEuler 22.03 LTS SP3 update for mod_security
- openEuler 24.03 LTS SP2 update for mod_security
- openEuler 22.03 LTS SP4 update for mod_security
- openEuler 22.03 LTS SP3 update for mod_security
- openEuler 24.03 LTS SP1 update for mod_security
- openEuler 24.03 LTS SP2 update for mod_security
- openEuler 24.03 LTS update for mod_security
- openEuler 24.03 LTS SP1 update for mod_security
- openEuler 24.03 LTS update for mod_security
- cPanel EasyApache4 update for third-party components
- openEuler 20.03 LTS SP4 update for mod_security
- SUSE update for apache2-mod_security2
- SUSE update for apache2-mod_security2
- Multiple vulnerabilities in Communications Unified Assurance
- Multiple vulnerabilities in Oracle HTTP Server
- Multiple vulnerabilities in Infrastructure Technology