Input validation error in OWASP ModSecurity Core Rule Set (CRS) - CVE-2022-39955
Published: February 9, 2023 / Updated: February 9, 2023
OWASP ModSecurity Core Rule Set (CRS)
OWASP
Description
The vulnerability allows a remote attacker to bypass filtration rules.
The vulnerability exists due to insufficient validation of user-supplied input when parsing HTTP Content-Type header field that indicates multiple character encoding schemes. A remote attacker send a specially crafted HTTP request and bypass the configurable CRS Content-Type header "charset" allow list.