Advisories ยป MGASA-2023-0175

Updated apache-mod_security packages fix security vulnerability

Publication date: 21 May 2023
Modification date: 21 May 2023
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-48279 , CVE-2023-24021

Description

HTTP multipart requests were incorrectly parsed and could bypass the Web
Application Firewall (CVE-2022-48279)
Incorrect handling of '\0' bytes in file uploads in ModSecurity may allow
for Web Application Firewall bypasses and buffer over-reads on the Web
Application Firewall when executing rules that read the FILES_TMP_CONTENT
collection. (CVE-2023-24021)
                

References

SRPMS

8/core