CVE-2022-39955 describes a critical partial rule set bypass vulnerability in the OWASP ModSecurity Core Rule Set (CRS) affecting versions 3.0.x, 3.1.x, 3.2.1, and 3.3.2. Attackers can exploit this by crafting HTTP Content-Type headers with multiple character encoding schemes, allowing encoded malicious payloads to bypass CRS detection and potentially be decoded by vulnerable backends. With a CVSS score of 9.8 (Critical), this network-exploitable vulnerability requires no user interaction or privileges and can lead to high impacts on confidentiality, integrity, and availability. While no public exploits (Metasploit, Nuclei, ExploitDB) or active exploitation have been identified, and community discussion is minimal, immediate upgrades to CRS 3.2.2 or 3.3.3 are strongly advised.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 3.2.2CPE matchmatch criteria | cpe:2.3:a:owasp:owasp_modsecurity_core_rule_set:*:*:*:*:*:*:*:* | ||
>= 3.3.0, < 3.3.3CPE matchmatch criteria | cpe:2.3:a:owasp:owasp_modsecurity_core_rule_set:*:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.