Request Body Bypass Vulnerability in OWASP ModSecurity Core Rule Set
CVE-2021-35368
9.8CRITICAL
Key Information:
- Vendor
Owasp
- Vendor
- CVE Published:
- 5 November 2021
What is CVE-2021-35368?
The OWASP ModSecurity Core Rule Set, in versions prior to 3.1.2, 3.2.1, and 3.3.2, is vulnerable to a Request Body Bypass due to improper handling of trailing pathnames. This flaw enables attackers to bypass core security rules intended to scrutinize incoming request bodies, potentially leading to unauthorized access and data exposure. Users should immediately update to the latest versions to mitigate this risk and protect their web applications from exploitation.
