Bug ID 1203104
Summary VUL-0: CVE-2020-22669: owasp-modsecurity-crs: SQL injection bypass
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/341471/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee Thomas.Worm@DATEV.de
Reporter thomas.leroy@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

CVE-2020-22669

Modsecurity owasp-modsecurity-crs 3.2.0 (Paranoia level at PL1) has a SQL
injection bypass vulnerability. Attackers can use the comment characters and
variable assignments in the SQL syntax to bypass Modsecurity WAF protection and
implement SQL injection attacks on Web applications.

Upstream PR:
https://github.com/coreruleset/coreruleset/pull/1793

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-22669
https://www.cve.org/CVERecord?id=CVE-2020-22669
https://github.com/coreruleset/coreruleset/pull/1793
https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/1727
http://www.cvedetails.com/cve/CVE-2020-22669/


You are receiving this mail because: