CVE-2020-22669
Last modified
CVE-2020-22669 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.. EPSS estimates a 0.99% chance of exploitation in the next 30 days.
Description
Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL injection bypass vulnerability. Attackers can use the comment characters and variable assignments in the SQL syntax to bypass Modsecurity WAF protection and implement SQL injection attacks on Web applications.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Owasp | Owasp Modsecurity Core Rule Set | 3.2.0 |
| Debian | Debian Linux | 10.0 |
References
- https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/1727Exploit, Issue Tracking, Third Party Advisory
- https://github.com/coreruleset/coreruleset/pull/1793Exploit, Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/01/msg00033.htmlMailing List, Third Party Advisory
- https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/1727Exploit, Issue Tracking, Third Party Advisory
- https://github.com/coreruleset/coreruleset/pull/1793Exploit, Issue Tracking, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2023/01/msg00033.htmlMailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-22669?
How severe is CVE-2020-22669?
How do I fix CVE-2020-22669?
Are you affected by CVE-2020-22669?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
