In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade mod_security-mlogcUpgrade mod_securityUpgrade mod_security-debuginfo | Jul 4, 2023 | Jan 20, 2023 |
| Amazon_linux | — | Upgrade mod24_securityUpgrade mod_security | Jun 9, 2023 | Jan 20, 2023 |
| Debian | — | Upgrade modsecurity-apacheUpgrade modsecurity | Jan 30, 2023 | Jan 20, 2023 |
| Huawei Euleros 2_0_sp5 | — | Upgrade mod_security | Jun 9, 2023 | Jan 20, 2023 |
| Huawei Euleros 2_0_sp8 | — | Upgrade mod_security | Apr 13, 2023 | Jan 20, 2023 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jan 20, 2023 |
| Suse | — | Upgrade apache2-mod_security2 | Feb 13, 2023 | Jan 20, 2023 |
| Ubuntu | — | Upgrade libapache2-modsecurity (Ubuntu Pro)Upgrade libapache2-mod-security2Upgrade libapache2-mod-security2 (Ubuntu Pro) | Sep 18, 2023 | Jan 20, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub