PT-2022-25144 · Owasp+1 · Owasp Modsecurity Core Rule Set+1

·

CVE-2022-39957

·

Published

2022-09-20

·

Updated

2025-08-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OWASP ModSecurity Core Rule Set (CRS) versions 3.0.x through 3.3.2
Description The issue concerns a response body bypass in the OWASP ModSecurity Core Rule Set (CRS). A client can exploit this by issuing an HTTP Accept header field with an optional charset parameter to receive the response in an encoded form. Depending on the charset, the response may not be decoded by the web application firewall, potentially allowing access to restricted resources without detection.
Recommendations For versions 3.0.x and 3.1.x, upgrade to version 3.2.2 or 3.3.3, respectively. For version 3.2.1, upgrade to version 3.2.2. For version 3.3.2, upgrade to version 3.3.3.

Exploit

Fix

Improper Encoding or Escaping of Output

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39957
DLA-3293-1
DLA-4265-1
MGASA-2024-0070
OESA-2022-1970

Affected Products

Debian
Owasp Modsecurity Core Rule Set