Input validation error in OWASP ModSecurity Core Rule Set (CRS) - CVE-2022-39956
Published: February 9, 2023
Vulnerability details
The vulnerability allows a remote attacker to bypass filtration rules.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and the rule set.
Affected software
Amazon Linux AMI
Gentoo Linux
openEuler
Fedora
mod_security
mod24_security
mod_security-debugsource
mod_security-debuginfo
mod_security_crs
www-apache/modsecurity-crs
How to mitigate CVE-2022-39956
mod_security - update to 2.8.0-5.28
mod24_security - update to 2.8.0-5.28
mod_security - addressed in versions 2.9.5-2, 2.9.5-3, 2.9.5-9, 2.9.9-1
mod_security-debugsource - addressed in versions 2.9.5-2, 2.9.5-3, 2.9.5-9, 2.9.9-1
mod_security-debuginfo - addressed in versions 2.9.5-2, 2.9.5-3, 2.9.5-9, 2.9.9-1
mod_security - addressed in versions 2.9.6-1.fc35, 2.9.6-1.fc36, 2.9.6-1.fc37
mod_security_crs - update to 3.2.2-1
www-apache/modsecurity-crs - update to 3.3.4
mod_security_crs - addressed in versions 3.3.4-1.fc35, 3.3.4-1.fc36, 3.3.4-1.fc37
External References
Related Security Bulletins
- Multiple vulnerabilities in OWASP ModSecurity Core Rule Set (CRS)
- Gentoo update for OWASP ModSecurity Core Rule Set
- Amazon Linux AMI update for mod_security
- Amazon Linux AMI update for mod24_security
- openEuler update for mod_security_crs
- openEuler 22.03 LTS SP3 update for mod_security
- openEuler 20.03 LTS SP1 update for mod_security
- openEuler 20.03 LTS SP4 update for mod_security
- openEuler 22.03 LTS update for mod_security
- openEuler 22.03 LTS SP1 update for mod_security
- openEuler 22.03 LTS SP2 update for mod_security
- Fedora 37 update for mod_security, mod_security_crs
- Fedora 36 update for mod_security, mod_security_crs
- Fedora 35 update for mod_security, mod_security_crs
- openEuler 22.03 LTS SP4 update for mod_security
- openEuler 22.03 LTS SP3 update for mod_security
- openEuler 20.03 LTS SP4 update for mod_security