CVE-2022-39956
published 2022-09-20CVE-2022-39956: The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.95%
57.3th percentile
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and the rule set. The multipart payload will therefore bypass detection. A vulnerable backend that supports these encoding schemes can potentially be exploited. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised upgrade to 3.2.2 and 3.3.3 respectively. The mitigation against these vulnerabilities depends on the installation of the latest ModSecurity version (v2.9.6 / v3.0.8).
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | modsecurity | < modsecurity 3.0.8-1 (bookworm) | modsecurity 3.0.8-1 (bookworm) |
| debian | modsecurity-apache | < modsecurity 3.0.8-1 (bookworm) | modsecurity 3.0.8-1 (bookworm) |
| debian | modsecurity-crs | < modsecurity-crs 3.3.4-1 (bookworm) | modsecurity-crs 3.3.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| owasp | modsecurity | >= 3.0.0 < 3.0.8 | 3.0.8 |
| owasp | owasp_modsecurity_core_rule_set | >= 3.0.0 < 3.2.2 | 3.2.2 |
| owasp | owasp_modsecurity_core_rule_set | >= 3.3.0 < 3.3.3 | 3.3.3 |
| trustwave | modsecurity | < 2.9.6 | 2.9.6 |
| trustwave | modsecurity | >= 0 < 3.0.8-1 | 3.0.8-1 |
| trustwave | modsecurity | >= 0 < 3.0.8-1 | 3.0.8-1 |
| trustwave | modsecurity | >= 0 < 3.0.8-1 | 3.0.8-1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2022-48279: In ModSecurity before 2
osv·2023-01-20·CVSS 9.8
CVE-2022-48279 [CRITICAL] CVE-2022-48279: In ModSecurity before 2
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
GHSA
GHSA-6fhx-fm6h-hpxq: In ModSecurity before 2
ghsa_unreviewed·2023-01-20·CVSS 7.3
CVE-2022-48279 [HIGH] CWE-269 GHSA-6fhx-fm6h-hpxq: In ModSecurity before 2
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
GHSA
GHSA-5xc6-pmr2-qj78: The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a cha
ghsa_unreviewed·2022-09-21
CVE-2022-39956 [CRITICAL] CWE-116 GHSA-5xc6-pmr2-qj78: The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a cha
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and the rule set. The multipart payload will therefore bypass detection. A vulnerable backend that supports these encoding schemes can potentially be exploited. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised upgrade to 3.2.2 and 3.3.3 respectively. The mitigation against these vulnerabilities depends on the installation of the latest ModSecurity versi
OSV
CVE-2022-39956: The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a cha
osv·2022-09-20·CVSS 9.8
CVE-2022-39956 [CRITICAL] CVE-2022-39956: The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a cha
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and the rule set. The multipart payload will therefore bypass detection. A vulnerable backend that supports these encoding schemes can potentially be exploited. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised upgrade to 3.2.2 and 3.3.3 respectively. The mitigation against these vulnerabilities depends on the installation of the latest ModSecurity versi
Red Hat
mod_security: incorrect parsing of HTTP multipart requests leads to web application firewall bypass
vendor_redhat·2023-01-20·CVSS 7.3
CVE-2022-48279 [HIGH] CWE-1389 mod_security: incorrect parsing of HTTP multipart requests leads to web application firewall bypass
mod_security: incorrect parsing of HTTP multipart requests leads to web application firewall bypass
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
A vulnerability was found in ModSecurity. This issue occurs when HTTP multipart requests are incorrectly parsed and could bypass the Web Application Firewall. NOTE: This is related to CVE-2022-39956, but can be considered independent changes to the ModSecurity (C language) codebase.
Statement: Red Hat rates this vulnerability as Moderate impact as a result of how mod_security is configured to be used in Red Hat products. Whe
Red Hat
mod_security_crs: Content-Type or Content-Transfer-Encoding MIME header fields abuse
vendor_redhat·2022-09-19·CVSS 7.3
CVE-2022-39956 [HIGH] CWE-863 mod_security_crs: Content-Type or Content-Transfer-Encoding MIME header fields abuse
mod_security_crs: Content-Type or Content-Transfer-Encoding MIME header fields abuse
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and the rule set. The multipart payload will therefore bypass detection. A vulnerable backend that supports these encoding schemes can potentially be exploited. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised upgrade to 3.2.2 and 3.3.3 respectively. The mitigation aga
Debian
CVE-2022-48279: modsecurity - In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were i...
vendor_debian·2022·CVSS 7.3
CVE-2022-48279 [HIGH] CVE-2022-48279: modsecurity - In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were i...
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
Scope: local
bookworm: resolved (fixed in 3.0.8-1)
bullseye: open
forky: resolved (fixed in 3.0.8-1)
sid: resolved (fixed in 3.0.8-1)
trixie: resolved (fixed in 3.0.8-1)
Debian
CVE-2022-39956: modsecurity-crs - The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypa...
vendor_debian·2022·CVSS 7.3
CVE-2022-39956 [HIGH] CVE-2022-39956: modsecurity-crs - The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypa...
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and the rule set. The multipart payload will therefore bypass detection. A vulnerable backend that supports these encoding schemes can potentially be exploited. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised upgrade to 3.2.2 and 3.3.3 respectively. The mitigation against these vulnerabilities depends on the installation of the latest ModSecurity versi
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://coreruleset.org/20220919/crs-version-3-3-3-and-3-2-2-covering-several-cves/https://lists.debian.org/debian-lts-announce/2023/01/msg00033.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HL2L2GF7GOCWPMJZDUE5OXDSXHGG3XUJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PD56EAYNGB6E6QQH62LAYCONOP6OH5DZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPQ6CCMX3MU4A7MTCGQJA7VMJW3IQDXV/https://security.gentoo.org/glsa/202305-25https://coreruleset.org/20220919/crs-version-3-3-3-and-3-2-2-covering-several-cves/https://lists.debian.org/debian-lts-announce/2023/01/msg00033.htmlhttps://lists.debian.org/debian-lts-announce/2025/08/msg00004.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HL2L2GF7GOCWPMJZDUE5OXDSXHGG3XUJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PD56EAYNGB6E6QQH62LAYCONOP6OH5DZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPQ6CCMX3MU4A7MTCGQJA7VMJW3IQDXV/https://security.gentoo.org/glsa/202305-25
2022-09-20
Published