<rss version="2.0"><channel><title>CVE-2023-38199 on CRS Project</title><link>https://0d2d0d50.website-1u6.pages.dev/tags/cve-2023-38199/</link><description>Recent content in CRS Project</description><item><title>CVE-2023-38199 – Multiple Content-Type Headers</title><link>https://0d2d0d50.website-1u6.pages.dev/20230717/cve-2023-38199-multiple-content-type-headers/</link><pubDate>Mon, 17 Jul 2023 10:57:39 +0200</pubDate><description>&lt;p&gt;The OWASP ModSecurity Core Rule Set (CRS) v3.3.4 does not detect the presence of multiple HTTP &amp;ldquo;Content-Type&amp;rdquo; header fields. As a result, on some platforms, it is possible to cause a CRS installation to process an HTTP request body differently (because of the different Content-Type) to how it would be processed by a backend web application.&lt;/p&gt;
&lt;p&gt;See the advisory at &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38199"&gt;https://nvd.nist.gov/vuln/detail/CVE-2023-38199&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update:&lt;/strong&gt; &lt;a href="https://coreruleset.org/20230724/crs-version-3-3-5-released/"&gt;CRS version 3.3.5 has now been released&lt;/a&gt; to address this vulnerability.&lt;/p&gt;</description></item></channel></rss>