CVE-2022-48279
mod_security: incorrect parsing of HTTP multipart requests leads to web application firewall bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
En ModSecurity anterior a 2.9.6 y 3.x anterior a 3.0.8, las solicitudes HTTP multiparte se analizaban incorrectamente y podían omitir el Firewall de aplicaciones web. NOTA: esto está relacionado con CVE-2022-39956, pero puede considerarse cambios independientes en el código base de ModSecurity (lenguaje C).
A vulnerability was found in ModSecurity. This issue occurs when HTTP multipart requests are incorrectly parsed and could bypass the Web Application Firewall. NOTE: This is related to CVE-2022-39956, but can be considered independent changes to the ModSecurity (C language) codebase.
Red Hat JBoss Core Services is a set of supplementary software for Red Hat JBoss middleware products. This software, such as Apache HTTP Server, is common to multiple JBoss middleware products and packaged under Red Hat JBoss Core Services, to allow for faster distribution of updates and for a more consistent update experience. This release of Red Hat JBoss Core Services Apache HTTP Server 2.4.57 serves as a replacement for Red Hat JBoss Core Services Apache HTTP Server 2.4.51 Service Pack 2, and includes bug fixes and enhancements, which are documented in the Release Notes document linked to in the References. Issues addressed include HTTP response splitting, bypass, integer overflow, out of bounds write, and use-after-free vulnerabilities.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-01-20 CVE Reserved
- 2023-01-20 CVE Published
- 2025-03-30 EPSS Updated
- 2025-04-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-436: Interpretation Conflict
- CWE-1389: Incorrect Parsing of Numbers with Different Radices
CAPEC
References (11)
URL | Tag | Source |
---|---|---|
https://coreruleset.org/20220919/crs-version-3-3-3-and-3-2-2-covering-several-cves | Not Applicable | |
https://github.com/SpiderLabs/ModSecurity/releases/tag/v2.9.6 | Release Notes | |
https://github.com/SpiderLabs/ModSecurity/releases/tag/v3.0.8 | Release Notes | |
https://lists.debian.org/debian-lts-announce/2023/01/msg00023.html | Mailing List |
|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/SpiderLabs/ModSecurity/pull/2795 | 2023-11-07 | |
https://github.com/SpiderLabs/ModSecurity/pull/2797 | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trustwave Search vendor "Trustwave" | Modsecurity Search vendor "Trustwave" for product "Modsecurity" | < 2.9.6 Search vendor "Trustwave" for product "Modsecurity" and version " < 2.9.6" | - |
Affected
| ||||||
Trustwave Search vendor "Trustwave" | Modsecurity Search vendor "Trustwave" for product "Modsecurity" | >= 3.0.0 < 3.0.8 Search vendor "Trustwave" for product "Modsecurity" and version " >= 3.0.0 < 3.0.8" | - |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 10.0 Search vendor "Debian" for product "Debian Linux" and version "10.0" | - |
Affected
|