Incorrect Regular Expression in OWASP ModSecurity Core Rule Set (CRS) - CVE-2019-11387
Published: February 9, 2023
OWASP ModSecurity Core Rule Set (CRS)
OWASP
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to incorrect ruleset in /rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf. A remote attacker can pass a specially crafted string with nested repetition operators and perform regular expression denial of service (ReDos) attack.