Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-48279

Опубликовано: 20 янв. 2023
Источник: debian

Описание

In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
modsecurity-apachefixed2.9.6-1package
modsecurity-apachefixed2.9.3-3+deb11u2bullseyepackage
modsecurityfixed3.0.8-1package
modsecurityno-dsabullseyepackage
modsecurityno-dsabusterpackage

Примечания

  • https://coreruleset.org/20220919/crs-version-3-3-3-and-3-2-2-covering-several-cves/

  • https://github.com/SpiderLabs/ModSecurity/pull/2795

  • Fixed by: https://github.com/SpiderLabs/ModSecurity/commit/d6c10885e08779e99e76efcd5ad65802104cda14 (v3.0.8)

  • https://github.com/SpiderLabs/ModSecurity/pull/2797

  • Fixed by: https://github.com/SpiderLabs/ModSecurity/commit/51a30d7b406af95c4143560d9753cf0b6d2151f5 (v2.9.6)

  • Issue relates to CVE-2022-39956 but considered independent change to ModSecurity (C

  • language) codebase.

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 2 лет назад

In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.

CVSS3: 7.5
redhat
больше 2 лет назад

In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.

CVSS3: 7.5
nvd
больше 2 лет назад

In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.

suse-cvrf
больше 2 лет назад

Security update for apache2-mod_security2

suse-cvrf
больше 2 лет назад

Security update for apache2-mod_security2