QID 355514
Date Published: 2023-07-03
QID 355514: Amazon Linux Security Advisory for mod_security : AL2012-2023-413
Package updates are available for Amazon Linux that fix the following vulnerabilities:
CVE-2022-48279:
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Administrators are advised to apply the appropriate software updates.
Vendor References
CVEs related to QID 355514
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| AL2012-2023-413 | Amazon Linux Bare Metal |
|