Vulnerability Description
Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAF security controls and send malicious HTTP POST requests to web servers behind the WAF.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Imperva | Web Application Firewall | < 2021-12-23 |
Related Weaknesses (CWE)
References
- https://bishopfox.com/blog/imperva-eliminates-critical-exposureExploitThird Party Advisory
- https://bishopfox.com/blog/imperva-eliminates-critical-exposureExploitThird Party Advisory
FAQ
What is CVE-2021-45468?
CVE-2021-45468 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Imperva Web Application Firewall (WAF) before 2021-12-23 allows remote unauthenticated attackers to use "Content-Encoding: gzip" to evade WAF security controls and send malicious HTTP POST requests to...
How severe is CVE-2021-45468?
CVE-2021-45468 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-45468?
Check the references section above for vendor advisories and patch information. Affected products include: Imperva Web Application Firewall.