CVE-2022-39955 | OWASP ModSecurity Core Rule Set up to 3.0.x/3.1.x/3.2.0/3.2.1 HTTP Header Content-Type authorization (FEDORA-2022-85a85c84b3)
A vulnerability described as critical has been identified in OWASP ModSecurity Core Rule Set up to 3.0.x/3.1.x/3.2.0/3.2.1. This impacts an unknown function of the component HTTP Header Handler. The manipulation of the argument Content-Type results in incorrect authorization.
This vulnerability is known as CVE-2022-39955. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.