CVE-2022-39957
published 2022-09-20CVE-2022-39957: The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional…
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.77%
51.5th percentile
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset", this response can not be decoded by the web application firewall. A restricted resource, access to which would ordinarily be detected, may therefore bypass detection. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised to upgrade to 3.2.2 and 3.3.3 respectively.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | modsecurity-crs | < modsecurity-crs 3.3.4-1 (bookworm) | modsecurity-crs 3.3.4-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| owasp | modsecurity_core_rule_set | — | — |
| owasp | modsecurity_core_rule_set | — | — |
| owasp | modsecurity_core_rule_set | unspecified – 3.2.1 | — |
| owasp | owasp_modsecurity_core_rule_set | >= 3.0.0 < 3.2.2 | 3.2.2 |
| owasp | owasp_modsecurity_core_rule_set | >= 3.3.0 < 3.3.3 | 3.3.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
mod_security_crs: Charset accept header field resulting in response rule set bypass
vendor_redhat·2022-09-19·CVSS 7.3
CVE-2022-39957 [HIGH] CWE-693 mod_security_crs: Charset accept header field resulting in response rule set bypass
mod_security_crs: Charset accept header field resulting in response rule set bypass
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset", this response can not be decoded by the web application firewall. A restricted resource, access to which would ordinarily be detected, may therefore bypass detection. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised to upgrade to 3.2.2 and 3.3.3 respectively.
A flaw was found in the OWASP ModSecurity Core Rule Set. A payload with a HTTP accept header field con
Debian
CVE-2022-39957: modsecurity-crs - The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass....
vendor_debian·2022·CVSS 7.3
CVE-2022-39957 [HIGH] CVE-2022-39957: modsecurity-crs - The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass....
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset", this response can not be decoded by the web application firewall. A restricted resource, access to which would ordinarily be detected, may therefore bypass detection. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised to upgrade to 3.2.2 and 3.3.3 respectively.
Scope: local
bookworm: resolved (fixed in 3.3.4-1)
bullseye: resolved (fixed in 3.3.4-1~deb11u1)
forky: resolved (fixed in 3.3.4-1)
sid: resolved (fixed in 3.3.4-1)
trixie: resolved (fixed
GHSA
GHSA-cxqq-h5hh-jgq2: The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass
ghsa_unreviewed·2022-09-21
CVE-2022-39957 [HIGH] CWE-116 GHSA-cxqq-h5hh-jgq2: The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset", this response can not be decoded by the web application firewall. A restricted resource, access to which would ordinarily be detected, may therefore bypass detection. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised to upgrade to 3.2.2 and 3.3.3 respectively.
OSV
CVE-2022-39957: The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass
osv·2022-09-20·CVSS 7.5
CVE-2022-39957 [HIGH] CVE-2022-39957: The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset", this response can not be decoded by the web application firewall. A restricted resource, access to which would ordinarily be detected, may therefore bypass detection. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised to upgrade to 3.2.2 and 3.3.3 respectively.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://coreruleset.org/20220919/crs-version-3-3-3-and-3-2-2-covering-several-cves/https://lists.debian.org/debian-lts-announce/2023/01/msg00033.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HL2L2GF7GOCWPMJZDUE5OXDSXHGG3XUJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PD56EAYNGB6E6QQH62LAYCONOP6OH5DZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPQ6CCMX3MU4A7MTCGQJA7VMJW3IQDXV/https://security.gentoo.org/glsa/202305-25https://coreruleset.org/20220919/crs-version-3-3-3-and-3-2-2-covering-several-cves/https://lists.debian.org/debian-lts-announce/2023/01/msg00033.htmlhttps://lists.debian.org/debian-lts-announce/2025/08/msg00004.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HL2L2GF7GOCWPMJZDUE5OXDSXHGG3XUJ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PD56EAYNGB6E6QQH62LAYCONOP6OH5DZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YPQ6CCMX3MU4A7MTCGQJA7VMJW3IQDXV/https://security.gentoo.org/glsa/202305-25
2022-09-20
Published