<rss version="2.0"><channel><title>CVE-2023-38199 on CRS Project</title><link>https://6a9cf20d.website-1u6.pages.dev/tags/cve-2023-38199/</link><description>Recent content in CRS Project</description><item><title>CVE-2023-38199 – Multiple Content-Type Headers</title><link>https://6a9cf20d.website-1u6.pages.dev/20230717/cve-2023-38199-multiple-content-type-headers/</link><pubDate>Mon, 17 Jul 2023 10:57:39 +0200</pubDate><description>&lt;p>The OWASP ModSecurity Core Rule Set (CRS) v3.3.4 does not detect the presence of multiple HTTP &amp;ldquo;Content-Type&amp;rdquo; header fields. As a result, on some platforms, it is possible to cause a CRS installation to process an HTTP request body differently (because of the different Content-Type) to how it would be processed by a backend web application.&lt;/p>
&lt;p>See the advisory at &lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38199">https://nvd.nist.gov/vuln/detail/CVE-2023-38199&lt;/a>.&lt;/p>
&lt;p>&lt;strong>Update:&lt;/strong> &lt;a href="https://coreruleset.org/20230724/crs-version-3-3-5-released/">CRS version 3.3.5 has now been released&lt;/a> to address this vulnerability.&lt;/p></description></item></channel></rss>