Skip to main content

Vendor/product archive

owasp / coreruleset CVEs

Beta · best-effort

1 CVEs tagged to owasp / coreruleset1 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2023-38199

Published Jul 13, 2023

coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might allow attackers to bypass a WAF…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1