CVE-2022-48279
20.01.2023, 19:15
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.Enginsight
Vendor | Product | Version |
---|---|---|
trustwave | modsecurity | 𝑥 < 2.9.6 |
trustwave | modsecurity | 3.0.0 ≤ 𝑥 < 3.0.8 |
debian | debian_linux | 10.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
modsecurity |
| ||||||||||||||||||
modsecurity-apache |
|
Common Weakness Enumeration
References