VDB

BIT-modsecurity2-2022-48279

BIT-modsecurity2-2022-48279 PUBLISHED CVSS 7.5 HIGH

In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Bitnamimodsecurity20, 0, 0

Timeline

  • Mar 6, 2024 CVE Published
  • Jul 4, 2025 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›