Input validation error in OWASP ModSecurity Core Rule Set (CRS) - CVE-2022-39956

 

Input validation error in OWASP ModSecurity Core Rule Set (CRS) - CVE-2022-39956

Published: February 9, 2023


Vulnerability identifier: #VU72089
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-39956
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass filtration rules.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and the rule set.


Affected software

OWASP ModSecurity Core Rule Set (CRS)
Amazon Linux AMI
Gentoo Linux
openEuler
Fedora
mod_security
mod24_security
mod_security-debugsource
mod_security-debuginfo
mod_security_crs
www-apache/modsecurity-crs

How to mitigate CVE-2022-39956

Install updates from vendor's website.

OWASP ModSecurity Core Rule Set (CRS) - addressed in versions 3.2.3, 3.3.4
mod_security - update to 2.8.0-5.28
mod24_security - update to 2.8.0-5.28
mod_security - addressed in versions 2.9.5-2, 2.9.5-3, 2.9.5-9, 2.9.9-1
mod_security-debugsource - addressed in versions 2.9.5-2, 2.9.5-3, 2.9.5-9, 2.9.9-1
mod_security-debuginfo - addressed in versions 2.9.5-2, 2.9.5-3, 2.9.5-9, 2.9.9-1
mod_security - addressed in versions 2.9.6-1.fc35, 2.9.6-1.fc36, 2.9.6-1.fc37
mod_security_crs - update to 3.2.2-1
www-apache/modsecurity-crs - update to 3.3.4
mod_security_crs - addressed in versions 3.3.4-1.fc35, 3.3.4-1.fc36, 3.3.4-1.fc37

External References

Related Security Bulletins