cbcvebase.
CVE-2022-39956
published 2022-09-20

CVE-2022-39956: The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character…

PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.95%
57.3th percentile
The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and the rule set. The multipart payload will therefore bypass detection. A vulnerable backend that supports these encoding schemes can potentially be exploited. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised upgrade to 3.2.2 and 3.3.3 respectively. The mitigation against these vulnerabilities depends on the installation of the latest ModSecurity version (v2.9.6 / v3.0.8).

Affected

14 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianmodsecurity< modsecurity 3.0.8-1 (bookworm)modsecurity 3.0.8-1 (bookworm)
debianmodsecurity-apache< modsecurity 3.0.8-1 (bookworm)modsecurity 3.0.8-1 (bookworm)
debianmodsecurity-crs< modsecurity-crs 3.3.4-1 (bookworm)modsecurity-crs 3.3.4-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
owaspmodsecurity>= 3.0.0 < 3.0.83.0.8
owaspowasp_modsecurity_core_rule_set>= 3.0.0 < 3.2.23.2.2
owaspowasp_modsecurity_core_rule_set>= 3.3.0 < 3.3.33.3.3
trustwavemodsecurity< 2.9.62.9.6
trustwavemodsecurity>= 0 < 3.0.8-13.0.8-1
trustwavemodsecurity>= 0 < 3.0.8-13.0.8-1
trustwavemodsecurity>= 0 < 3.0.8-13.0.8-1

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.