In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
2023-01-20T19:15:17.783
2025-07-03T20:59:18.650
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | owasp | modsecurity | < 3.0.8 | Yes |
Application | trustwave | modsecurity | < 2.9.6 | Yes |
Operating System | debian | debian_linux | 10.0 | Yes |