ModSecurity Vulnerabilities Let Attackers Bypass WAF Rules
ID: 3aa5d28b-854d-5774-9afa-f8d8203953d5
STIX ID: report--3aa5d28b-854d-5774-9afa-f8d8203953d5
Feed Name: securityonline.info
TL;DR: OWASP ModSecurity released v3.0.16 to fix two rule-bypass vulnerabilities in ModSecurity v3.0.15 and earlier — a high-severity multipart/form-data parser bug that removes embedded line breaks and can hide payloads from WAF rules (CVSS 8.6), and an i386-specific t:utf8toUnicode transformation error that can be evaded on 32-bit builds (CVSS 5.8). The advisory notes wide impact because ModSecurity is a commonly deployed WAF engine on Apache, Nginx, and IIS, reports no confirmed exploitation in the wild, and recommends immediate upgrade to 3.0.16, reviewing multipart rules, and avoiding i386 builds.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
