CVE-2024-1019 describes a WAF bypass vulnerability affecting ModSecurity and libModSecurity versions 3.0.0 to 3.0.11. This flaw allows attackers to hide malicious payloads within specially crafted request URLs, which ModSecurity v3 decodes before separating the path and query string, leading to an impedance mismatch with RFC-compliant backend applications. The vulnerability carries a high CVSS score of 8.6, indicating a critical severity. It is a network-based attack with low attack complexity, requiring no user interaction or privileges, and can result in high integrity impact by allowing attackers to bypass WAF rules and potentially manipulate backend queries. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.0.12CPE matchmatch criteria | cpe:2.3:a:owasp:modsecurity:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.