PT-2022-25145 · Owasp+1 · Owasp Modsecurity Core Rule Set+1

Hussein98D

+2

·

Published

2022-09-20

·

Updated

2025-08-09

·

CVE-2022-39958

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OWASP ModSecurity Core Rule Set (CRS) versions 3.0.x through 3.3.2
Description The issue allows for a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, access to which would ordinarily be detected, may be exfiltrated from the backend, despite being protected by a web application firewall that uses CRS. Short subsections of a restricted resource may bypass pattern matching techniques and allow undetected access.
Recommendations To resolve the issue, upgrade to version 3.2.2 if currently using version 3.2.1, and upgrade to version 3.3.3 if currently using version 3.3.2. Additionally, configure a CRS paranoia level of 3 or higher. For versions 3.0.x and 3.1.x, upgrade to a supported version and then apply the aforementioned recommendations.

Fix

Incorrect Authorization

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

CVE-2022-39958
DLA-3293-1
DLA-4265-1
MGASA-2024-0070
OESA-2022-1970

Affected Products

Debian
Owasp Modsecurity Core Rule Set