go package github.com/corazawaf/coraza is vulnerable to denial of service
CVE-2023-40586

7.5HIGH

Key Information:

Vendor

Corazawaf

Status
Vendor
CVE Published:
25 August 2023

What is CVE-2023-40586?

A vulnerability in the OWASP Coraza WAF allows attackers to exploit a flaw in the application's error handling mechanism. When receiving specifically crafted requests, Coraza crashes due to improper processing in the mime.ParseMediaType function, which is triggered by the misuse of log.Fatalf. This issue has been resolved in version 3.0.1, making it critical for users to upgrade to the latest version to mitigate the risk of application downtime.

Affected Version(s)

coraza < 3.0.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.