CVE-2022-48279: High severity Trustwave ModSecurity vulnerability
A vulnerability was found in ModSecurity. This issue occurs when HTTP multipart requests are incorrectly parsed and could bypass the Web Application Firewall. NOTE: This is related to CVE-2022-39956, but can be considered independent changes to the ModSecurity (C language) codebase.
Other sources
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
— Ubuntu
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ubuntu/modsecurityto a version that resolves this vulnerability.Fixed in 3.0.8-1 - Upgrade
Upgrade
ubuntu/modsecurity-apacheto a version that resolves this vulnerability.Fixed in 2.9.5-1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/modsecurity-apacheto a version that resolves this vulnerability.Fixed in 2.9.0-1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/modsecurity-apacheto a version that resolves this vulnerability.Fixed in 2.9.2-1ubuntu0.1~ - Upgrade
Upgrade
ubuntu/modsecurity-apacheto a version that resolves this vulnerability.Fixed in 2.9.3-1ubuntu0.1 - Upgrade
Upgrade
ubuntu/modsecurity-apacheto a version that resolves this vulnerability.Fixed in 2.7.7-2ubuntu0.1~ - Upgrade
Upgrade
ubuntu/modsecurity-apacheto a version that resolves this vulnerability.Fixed in 2.9.6-1 - Upgrade
Upgrade
debian/modsecurityto a version that resolves this vulnerability.Fixed in 3.0.9-1+deb12u1Fixed in 3.0.12-1 - Upgrade
Upgrade
debian/modsecurity-apacheto a version that resolves this vulnerability.Fixed in 2.9.3-1+deb10u2Fixed in 2.9.3-3+deb11u2Fixed in 2.9.7-1 - Upgrade
Upgrade
redhat/ModSecurityto a version that resolves this vulnerability.Fixed in 2.9.6 - Upgrade
Upgrade
redhat/ModSecurityto a version that resolves this vulnerability.Fixed in 3.0.8 - Upgrade
Upgrade
ModSecurityto a version that resolves this vulnerability.Fixed in 2.9.6 - Upgrade
Upgrade
ModSecurityto a version that resolves this vulnerability.Fixed in 3.0.8
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-48279?
CVE-2022-48279 is a vulnerability found in ModSecurity that allows HTTP multipart requests to be incorrectly parsed, bypassing the Web Application Firewall.
What is the severity of CVE-2022-48279?
CVE-2022-48279 has a severity rating of 7.5, which is considered high.
Which software versions are affected by CVE-2022-48279?
ModSecurity versions before 2.9.6 and 3.x before 3.0.8 are affected by CVE-2022-48279.
How can I fix CVE-2022-48279?
To fix CVE-2022-48279, upgrade ModSecurity to version 2.9.6 or 3.0.8 or a later version.
Is CVE-2022-48279 related to CVE-2022-39956?
Yes, CVE-2022-48279 is related to CVE-2022-39956, but they can be considered independent changes to the ModSecurity codebase.