CVE-2023-38199
Published Jul 13, 2023coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might allow attackers to bypass a WAF…
Vendor/product archive
1 CVEs tagged to owasp / coreruleset — 1 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.
coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might allow attackers to bypass a WAF…