PT-2022-25143 · Owasp+1 · Owasp Modsecurity Core Rule Set+1

Jan Gora

+1

·

Published

2022-09-20

·

Updated

2025-08-09

·

CVE-2022-39956

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OWASP ModSecurity Core Rule Set (CRS) versions 3.0.x through 3.3.2
Description The issue concerns a partial rule set bypass for HTTP multipart requests. This occurs when a payload uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields. As a result, the web application firewall engine and the rule set will not decode and inspect the payload, allowing it to bypass detection. A vulnerable backend that supports these encoding schemes can potentially be exploited.
Recommendations For versions 3.0.x and 3.1.x, upgrade to version 3.2.2 or 3.3.3, respectively. For version 3.2.1, upgrade to version 3.2.2. For version 3.3.2, upgrade to version 3.3.3. As a general mitigation measure, install the latest ModSecurity version (v2.9.6 / v3.0.8).

Fix

Incorrect Authorization

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2022-39956
DLA-3283-1
DLA-3293-1
DLA-4265-1
MGASA-2024-0070
OESA-2022-1964
OESA-2025-1559
OESA-2025-1560
OESA-2025-1561

Affected Products

Debian
Owasp Modsecurity Core Rule Set