7.5
CVSSv2

CVE-2021-35368

Published: 05/11/2021 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

OWASP ModSecurity Core Rule Set 3.1.x prior to 3.1.2, 3.2.x prior to 3.2.1, and 3.3.x prior to 3.3.2 is affected by a Request Body Bypass via a trailing pathname.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

owasp owasp modsecurity core rule set

fedoraproject fedora 36

fedoraproject fedora 37

debian debian linux 10.0

Vendor Advisories

Debian Bug report logs - #992000 modsecurity-crs: Needs update to 332 for CVE-2021-35368 Package: modsecurity-crs; Maintainer for modsecurity-crs is Alberto Gonzalez Iniesta <agi@inittaborg>; Source for modsecurity-crs is src:modsecurity-crs (PTS, buildd, popcon) Reported by: Frederik Himpe <frederik@frehibe> Dat ...