coreruleset (aka OWASP ModSecurity Core Rule Set) through...
Critical severity
Unreviewed
Published
Jul 13, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Jul 13, 2023
Published to the GitHub Advisory Database
Jul 13, 2023
Last updated
Apr 4, 2024
coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not block multiple Content-Type headers, which might allow attackers to bypass a WAF with a crafted payload, aka "Content-Type confusion." This occurs when the web application relies on only the last Content-Type header.
References