I was able to bypass @azure WAF with OWASP 3.2 Managed Rule Set using bash standard wildcards.

Example: If we want to execute cat /etc/passwd command, the we can use /bin/cat /et?/passwo?d

The issue was fixed last year on 16 Jul 2021. No bounty was awarded. https://t.co/xbMmH1KWgE