CVE-2021-35368: OWASP ModSecurity Core Rule Set security release
Christian Folini <[email protected]> Wed, 30 Jun 2021 16:30:33 +0200
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <20210630143033.GB609637@leander> |
Dear all, The OWASP ModSecurity Core Rule Set team has published the following releases: * v3.3.2 (supported) * v3.2.1 (supported) * v3.1.2 (EOL) All these releases are meant to fight CVE-2021-35368, a CRS request body bypass vulnerability. Details about the vulnerability as well as links to release files and changelog can be found here: https://coreruleset.org/20210630/cve-2021-35368-crs-request-body-bypass/ Please note that this is a CRS problem and has nothing to do with the engine ModSecurity. The changeset is minimal, so an update should be smooth. Best regards, Christian Folini, CRS Co-Lead -- Had I been present at the creation, I would have given some useful hints for the better ordering of the universe. -- Alfonso the Wise, 1221 - 1284 _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/