Input validation error in OWASP ModSecurity Core Rule Set (CRS) - CVE-2022-39955
Published: February 9, 2023 / Updated: February 9, 2023
Vulnerability details
The vulnerability allows a remote attacker to bypass filtration rules.
The vulnerability exists due to insufficient validation of user-supplied input when parsing HTTP Content-Type header field that indicates multiple character encoding schemes. A remote attacker send a specially crafted HTTP request and bypass the configurable CRS Content-Type header "charset" allow list.
Affected software
Gentoo Linux
openEuler
Fedora
mod_security
mod_security_crs
www-apache/modsecurity-crs
How to mitigate CVE-2022-39955
mod_security - addressed in versions 2.9.6-1.fc35, 2.9.6-1.fc36, 2.9.6-1.fc37
mod_security_crs - update to 3.2.2-1
www-apache/modsecurity-crs - update to 3.3.4
mod_security_crs - addressed in versions 3.3.4-1.fc35, 3.3.4-1.fc36, 3.3.4-1.fc37
External References
Related Security Bulletins
- Multiple vulnerabilities in OWASP ModSecurity Core Rule Set (CRS)
- Gentoo update for OWASP ModSecurity Core Rule Set
- openEuler update for mod_security_crs
- Fedora 37 update for mod_security, mod_security_crs
- Fedora 36 update for mod_security, mod_security_crs
- Fedora 35 update for mod_security, mod_security_crs