OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`, the application using coraza crashed after receiving crafted requests from attackers. The application will immediately crash after receiving a malicious request that triggers an error in `mime.ParseMediaType`. This issue was patched in version 3.0.1.
CVSS
No CVSS.
References
Configurations
No configuration.
History
25 Aug 2023, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-08-25 21:15
Updated : 2023-08-26 04:05
NVD link : CVE-2023-40586
Mitre link : CVE-2023-40586
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption