Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-33691

Опубликовано: 02 апр. 2026
Источник: debian
EPSS Низкий

Описание

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This issue has been patched in versions 3.3.9 and 4.25.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
modsecurity-crsfixed3.3.9-1package
modsecurity-crsfixed3.3.7-1+deb13u2trixiepackage
modsecurity-crsfixed3.3.4-1+deb12u3bookwormpackage
modsecurity-crspostponedbullseyepackage

Примечания

  • https://github.com/coreruleset/coreruleset/security/advisories/GHSA-rw5f-9w43-gv2w

EPSS

Процентиль: 88%
0.03579
Низкий

Связанные уязвимости

CVSS3: 6.8
ubuntu
5 месяцев назад

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This issue has been patched in versions 3.3.9 and 4.25.0.

CVSS3: 6.8
nvd
5 месяцев назад

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This issue has been patched in versions 3.3.9 and 4.25.0.

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость балансировщика нагрузки Progress Kemp LoadMaster, связанная с непринятием мер по очистке данных на управляющем уровне, позволяющая нарушителю выполнять произвольные команды

EPSS

Процентиль: 88%
0.03579
Низкий