{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Moderate"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "DoS Vulnerability in Four Transformations",
    "tracking": {
      "current_release_date": "2026-08-11T17:01:44+00:00",
      "generator": {
        "date": "2026-08-11T17:01:44+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.3.0"
        }
      },
      "id": "CVE-2023-38285",
      "initial_release_date": "2023-07-26T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2026-08-11T17:01:44+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7-els",
            "product": {
              "name": "Red Hat Enterprise Linux 7-els",
              "product_id": "rhel-7-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:7"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.10.z",
            "product": {
              "name": "Red Hat Enterprise Linux 8.10.z",
              "product_id": "rhel-8",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:8"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 9.9",
            "product": {
              "name": "Red Hat Enterprise Linux 9.9",
              "product_id": "rhel-9",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:9"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Software Collections",
            "product": {
              "name": "Red Hat Software Collections",
              "product_id": "rhscl-3",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:rhel_software_collections:3"
              }
            }
          },
          {
            "category": "product_version",
            "name": "httpd24-mlogc",
            "product": {
              "name": "httpd24-mlogc",
              "product_id": "httpd24-mlogc",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/httpd24-mlogc"
              }
            }
          },
          {
            "category": "product_version",
            "name": "httpd24-mod_security",
            "product": {
              "name": "httpd24-mod_security",
              "product_id": "httpd24-mod_security",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/httpd24-mod_security"
              }
            }
          },
          {
            "category": "product_version",
            "name": "httpd24-mod_security",
            "product": {
              "name": "httpd24-mod_security",
              "product_id": "httpd24-mod_security.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/httpd24-mod_security?arch=src"
              }
            }
          },
          {
            "category": "product_version",
            "name": "mod_security",
            "product": {
              "name": "mod_security",
              "product_id": "mod_security",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/mod_security"
              }
            }
          },
          {
            "category": "product_version",
            "name": "mod_security-debuginfo",
            "product": {
              "name": "mod_security-debuginfo",
              "product_id": "mod_security-debuginfo",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/mod_security-debuginfo"
              }
            }
          },
          {
            "category": "product_version",
            "name": "mod_security-mlogc",
            "product": {
              "name": "mod_security-mlogc",
              "product_id": "mod_security-mlogc",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/mod_security-mlogc"
              }
            }
          },
          {
            "category": "product_version",
            "name": "mod_security",
            "product": {
              "name": "mod_security",
              "product_id": "mod_security.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/mod_security?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd24-mlogc as a component of Red Hat Software Collections",
          "product_id": "rhscl-3:httpd24-mlogc"
        },
        "product_reference": "httpd24-mlogc",
        "relates_to_product_reference": "rhscl-3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd24-mod_security as a component of Red Hat Software Collections",
          "product_id": "rhscl-3:httpd24-mod_security"
        },
        "product_reference": "httpd24-mod_security",
        "relates_to_product_reference": "rhscl-3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "httpd24-mod_security.src as a component of Red Hat Software Collections",
          "product_id": "rhscl-3:httpd24-mod_security.src"
        },
        "product_reference": "httpd24-mod_security.src",
        "relates_to_product_reference": "rhscl-3"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_security as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:mod_security"
        },
        "product_reference": "mod_security",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_security as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:mod_security"
        },
        "product_reference": "mod_security",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_security as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:mod_security"
        },
        "product_reference": "mod_security",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_security-debuginfo as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:mod_security-debuginfo"
        },
        "product_reference": "mod_security-debuginfo",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_security-mlogc as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:mod_security-mlogc"
        },
        "product_reference": "mod_security-mlogc",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_security-mlogc as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:mod_security-mlogc"
        },
        "product_reference": "mod_security-mlogc",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_security-mlogc as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:mod_security-mlogc"
        },
        "product_reference": "mod_security-mlogc",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_security.src as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:mod_security.src"
        },
        "product_reference": "mod_security.src",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_security.src as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:mod_security.src"
        },
        "product_reference": "mod_security.src",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "mod_security.src as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:mod_security.src"
        },
        "product_reference": "mod_security.src",
        "relates_to_product_reference": "rhel-7-els.els"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-38285",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "discovery_date": "2023-07-27T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhel-7-els.els:mod_security",
            "rhel-7-els.els:mod_security-debuginfo",
            "rhel-7-els.els:mod_security-mlogc",
            "rhel-7-els.els:mod_security.src",
            "rhel-8:mod_security",
            "rhel-8:mod_security-mlogc",
            "rhel-8:mod_security.src",
            "rhel-9:mod_security",
            "rhel-9:mod_security-mlogc",
            "rhel-9:mod_security.src",
            "rhscl-3:httpd24-mlogc",
            "rhscl-3:httpd24-mod_security",
            "rhscl-3:httpd24-mod_security.src"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "ModSecurity v2.x is not affected. CVE-2023-38285 only affects ModSecurity v3.x releases. None of our products ship ModSecurity v3.x builds. Therefore, Red Hat Enterprise Linux, Red Hat Software Collections, and Red Hat JBoss Core Services are not affected by this CVE.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "A vulnerability was found in Trustwave's ModSecurity project due to an inefficient algorithmic complexity flaw. This issue is present in four transformation actions: removeWhitespace, removeNull, replaceNull, and removeCommentsChar. By sending a maliciously crafted HTTP request, an attacker could trigger worst-case performance, causing a denial of service.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "rhel-7-els.els:mod_security",
          "rhel-7-els.els:mod_security-debuginfo",
          "rhel-7-els.els:mod_security-mlogc",
          "rhel-7-els.els:mod_security.src",
          "rhel-8:mod_security",
          "rhel-8:mod_security-mlogc",
          "rhel-8:mod_security.src",
          "rhel-9:mod_security",
          "rhel-9:mod_security-mlogc",
          "rhel-9:mod_security.src",
          "rhscl-3:httpd24-mlogc",
          "rhscl-3:httpd24-mod_security",
          "rhscl-3:httpd24-mod_security.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2023-38285"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-38285"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-38285"
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "baseScore": 7.5,
            "baseSeverity": "HIGH"
          },
          "products": [
            "rhel-7-els.els:mod_security",
            "rhel-7-els.els:mod_security-debuginfo",
            "rhel-7-els.els:mod_security-mlogc",
            "rhel-7-els.els:mod_security.src",
            "rhel-8:mod_security",
            "rhel-8:mod_security-mlogc",
            "rhel-8:mod_security.src",
            "rhel-9:mod_security",
            "rhel-9:mod_security-mlogc",
            "rhel-9:mod_security.src",
            "rhscl-3:httpd24-mlogc",
            "rhscl-3:httpd24-mod_security",
            "rhscl-3:httpd24-mod_security.src"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate",
          "product_ids": [
            "rhel-7-els.els:mod_security",
            "rhel-7-els.els:mod_security-debuginfo",
            "rhel-7-els.els:mod_security-mlogc",
            "rhel-7-els.els:mod_security.src",
            "rhel-8:mod_security",
            "rhel-8:mod_security-mlogc",
            "rhel-8:mod_security.src",
            "rhel-9:mod_security",
            "rhel-9:mod_security-mlogc",
            "rhel-9:mod_security.src",
            "rhscl-3:httpd24-mlogc",
            "rhscl-3:httpd24-mod_security",
            "rhscl-3:httpd24-mod_security.src"
          ]
        }
      ],
      "title": "DoS Vulnerability in Four Transformations"
    }
  ]
}