Lucene search

K
cveMitreCVE-2023-38199
HistoryJul 13, 2023 - 3:15 a.m.

CVE-2023-38199

2023-07-1303:15:10
CWE-843
mitre
web.nvd.nist.gov
27
20
cve-2023-38199
owasp modsecurity
content-type confusion
waf bypass
security vulnerability
nvd
information security

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

52.7%

coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might allow attackers to bypass a WAF with a crafted payload, aka “Content-Type confusion” between the WAF and the backend application. This occurs when the web application relies on only the last Content-Type header. Other platforms may reject the additional Content-Type header or merge conflicting headers, leading to detection as a malformed header.

Affected configurations

Nvd
Node
owaspcorerulesetRange3.3.4
VendorProductVersionCPE
owaspcoreruleset*cpe:2.3:a:owasp:coreruleset:*:*:*:*:*:*:*:*

Social References

More

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.002

Percentile

52.7%