« Volver al listado

CVE-2008-5676

Estado: ModificadaMedia (5)—

Multiple unspecified vulnerabilities in the ModSecurity (aka mod_security) module 2.5.0 through 2.5.5 for the Apache HTTP Server, when SecCacheTransformations is enabled, allow remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors related to "transformation caching."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-5676",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-12-19T01:52:58.017",
  "references": [
    {
      "url": "http://blog.modsecurity.org/2008/08/transformation.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://freshmeat.net/projects/modsecurity/?branch_id=34901&release_id=282329",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/32146",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2795",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45770",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://blog.modsecurity.org/2008/08/transformation.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://freshmeat.net/projects/modsecurity/?branch_id=34901&release_id=282329",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/32146",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/2795",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45770",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple unspecified vulnerabilities in the ModSecurity (aka mod_security) module 2.5.0 through 2.5.5 for the Apache HTTP Server, when SecCacheTransformations is enabled, allow remote attackers to cause a denial of service (daemon crash) or bypass the product's functionality via unknown vectors related to \"transformation caching.\""
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades inespecificas en el modulo ModSecurity (anteriormente conocido como mod_security) desde v2.5.0 hasta v2.5.5 para el servidor HTTP de Apache, cuando SecCacheTransformations esta activado, permite a atacantes remotos producir una denegación de servicio (caída de demonio) o evitar la funcionalidad del producto a través de vectores desconocidos relacionados con el \"transformation caching\"."
    }
  ],
  "lastModified": "2026-06-16T23:00:46.950",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:breach:modsecurity:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6B7C132-C6D8-4AEB-A960-20F36B06442B",
              "versionEndIncluding": "2.5.0"
            },
            {
              "criteria": "cpe:2.3:a:breach:modsecurity:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F2C45DD-48A4-4BA9-8411-F12ECE52D7AC",
              "versionEndIncluding": "2.5.5"
            },
            {
              "criteria": "cpe:2.3:a:breach:modsecurity:2.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBFEDDD5-E233-48A3-B7C3-BD894206E760"
            },
            {
              "criteria": "cpe:2.3:a:breach:modsecurity:2.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F3F5973-A3E8-4C75-AFC1-E49E905F6537"
            },
            {
              "criteria": "cpe:2.3:a:breach:modsecurity:2.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51952413-5086-49A4-B592-0AADF38F942A"
            },
            {
              "criteria": "cpe:2.3:a:breach:modsecurity:2.5.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76270534-F275-4AB1-849E-D9F224ACCEE8"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}