PT-2022-25143 · Owasp+1 · Owasp Modsecurity Core Rule Set+1
Jan Gora
+1
·
Published
2022-09-20
·
Updated
2025-08-09
·
CVE-2022-39956
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OWASP ModSecurity Core Rule Set (CRS) versions 3.0.x through 3.3.2
Description
The issue concerns a partial rule set bypass for HTTP multipart requests. This occurs when a payload uses a character encoding scheme via the
Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields. As a result, the web application firewall engine and the rule set will not decode and inspect the payload, allowing it to bypass detection. A vulnerable backend that supports these encoding schemes can potentially be exploited.Recommendations
For versions 3.0.x and 3.1.x, upgrade to version 3.2.2 or 3.3.3, respectively.
For version 3.2.1, upgrade to version 3.2.2.
For version 3.3.2, upgrade to version 3.3.3.
As a general mitigation measure, install the latest ModSecurity version (v2.9.6 / v3.0.8).
Fix
Incorrect Authorization
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Owasp Modsecurity Core Rule Set