cbcvebase.
CVE-2022-39957
published 2022-09-20

CVE-2022-39957: The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional…

PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.77%
51.5th percentile
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded form. Depending on the "charset", this response can not be decoded by the web application firewall. A restricted resource, access to which would ordinarily be detected, may therefore bypass detection. The legacy CRS versions 3.0.x and 3.1.x are affected, as well as the currently supported versions 3.2.1 and 3.3.2. Integrators and users are advised to upgrade to 3.2.2 and 3.3.3 respectively.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianmodsecurity-crs< modsecurity-crs 3.3.4-1 (bookworm)modsecurity-crs 3.3.4-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
owaspmodsecurity_core_rule_set
owaspmodsecurity_core_rule_set
owaspmodsecurity_core_rule_setunspecified – 3.2.1
owaspowasp_modsecurity_core_rule_set>= 3.0.0 < 3.2.23.2.2
owaspowasp_modsecurity_core_rule_set>= 3.3.0 < 3.3.33.3.3

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.