NA

CVE-2022-48279

Published: 20/01/2023 Updated: 07/11/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

In ModSecurity prior to 2.9.6 and 3.x prior to 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

trustwave modsecurity

debian debian linux 10.0

Vendor Advisories

Synopsis Moderate: Red Hat JBoss Core Services Apache HTTP Server 2457 security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat JBoss Core ServicesRed Hat Product Security h ...
Synopsis Moderate: Red Hat JBoss Core Services Apache HTTP Server 2457 security update Type/Severity Security Advisory: Moderate Topic Red Hat JBoss Core Services Apache HTTP Server 2457 is now availableRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) bas ...
In ModSecurity before 296 and 3x before 308, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase (CVE-2022-48279) In ModSecurity before 297, FILES_TMP_CONTENT sometimes lacked ...
In ModSecurity before 296 and 3x before 308, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase (CVE-2022-48279) ...
In ModSecurity before 296 and 3x before 308, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase (CVE-2022-48279) ...
Description<!---->A vulnerability was found in ModSecurity This issue occurs when HTTP multipart requests are incorrectly parsed and could bypass the Web Application Firewall NOTE: This is related to CVE-2022-39956, but can be considered independent changes to the ModSecurity (C language) codebaseA vulnerability was found in ModSecurity This is ...