Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-33691

Опубликовано: 02 апр. 2026
Источник: nvd
CVSS3: 6.8
CVSS3: 7.5
EPSS Низкий

Описание

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This issue has been patched in versions 3.3.9 and 4.25.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:owasp:owasp_modsecurity_core_rule_set:*:*:*:*:*:*:*:*
Версия до 3.3.9 (исключая)
cpe:2.3:a:owasp:owasp_modsecurity_core_rule_set:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.25.0 (исключая)

EPSS

Процентиль: 88%
0.03579
Низкий

6.8 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-178

Связанные уязвимости

CVSS3: 6.8
ubuntu
5 месяцев назад

The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). The affected rules do not normalize whitespace before evaluating the file extension regex, so the dot-extension check fails to match. This issue has been patched in versions 3.3.9 and 4.25.0.

CVSS3: 6.8
debian
5 месяцев назад

The OWASP core rule set (CRS) is a set of generic attack detection rul ...

CVSS3: 9.8
fstec
3 месяца назад

Уязвимость балансировщика нагрузки Progress Kemp LoadMaster, связанная с непринятием мер по очистке данных на управляющем уровне, позволяющая нарушителю выполнять произвольные команды

EPSS

Процентиль: 88%
0.03579
Низкий

6.8 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-178