Description
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3283-1 | modsecurity-apache security update |
EUVD |
EUVD-2022-50981 | In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase. |
Ubuntu USN |
USN-6370-1 | ModSecurity vulnerabilities |
References
History
Thu, 03 Jul 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Owasp
Owasp modsecurity |
|
| CPEs | cpe:2.3:a:owasp:modsecurity:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Owasp
Owasp modsecurity |
Thu, 03 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-03T18:43:26.152Z
Reserved: 2023-01-20T00:00:00.000Z
Link: CVE-2022-48279
Updated: 2024-08-03T15:10:59.557Z
Status : Modified
Published: 2023-01-20T19:15:17.783
Modified: 2025-07-03T20:59:18.650
Link: CVE-2022-48279
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN