CVE Vulnerabilities

CVE-2019-25043

Improper Handling of Exceptional Conditions

Published: May 06, 2021 | Modified: Jul 03, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

ModSecurity 3.x before 3.0.4 mishandles key-value pair parsing, as demonstrated by a string index out of range error and worker-process crash for a Cookie: =abc header.

Weakness

The product does not handle or incorrectly handles an exceptional condition.

Affected Software

Name Vendor Start Version End Version
Modsecurity Owasp 3.0.0 (including) 3.0.4 (excluding)
Modsecurity Ubuntu focal *
Modsecurity Ubuntu groovy *
Modsecurity Ubuntu hirsute *
Modsecurity Ubuntu impish *
Modsecurity Ubuntu kinetic *
Modsecurity Ubuntu lunar *
Modsecurity Ubuntu mantic *
Modsecurity Ubuntu oracular *
Modsecurity Ubuntu trusty *
Modsecurity Ubuntu xenial *

References