CVE-2023-40586

CVSS V2 None CVSS V3 None
Description
OWASP Coraza WAF is a golang modsecurity compatible web application firewall library. Due to the misuse of `log.Fatalf`, the application using coraza crashed after receiving crafted requests from attackers. The application will immediately crash after receiving a malicious request that triggers an error in `mime.ParseMediaType`. This issue was patched in version 3.0.1.
Overview
  • CVE ID
  • CVE-2023-40586
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-08-25T20:35:27.459Z
  • Last Modified Date
  • 2023-08-25T20:35:27.459Z
History
Created Old Value New Value Data Type Notes
2024-06-25 02:24:42 Added to TrackCVE