Input validation error in ModSecurity - CVE-2013-1915

 

Input validation error in ModSecurity - CVE-2013-1915

Published: April 26, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU42869
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-1915
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to read and manipulate data.

ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.


Affected software

ModSecurity
Fedora
mod_security

How to mitigate CVE-2013-1915

Install update from vendor's website.

mod_security - addressed in versions 2.6.8-3.el5, 2.7.3-1.el6

External References

Related Security Bulletins