CVE-2021-35368: OWASP ModSecurity Core Rule Set security release

Christian Folini <[email protected]> Wed, 30 Jun 2021 16:30:33 +0200
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <20210630143033.GB609637@leander>
Dear all,

The OWASP ModSecurity Core Rule Set team has published the following releases:

* v3.3.2 (supported)
* v3.2.1 (supported)
* v3.1.2 (EOL)

All these releases are meant to fight CVE-2021-35368, a CRS request body
bypass vulnerability.

Details about the vulnerability as well as links to release files and
changelog can be found here:

https://coreruleset.org/20210630/cve-2021-35368-crs-request-body-bypass/

Please note that this is a CRS problem and has nothing to do with the engine
ModSecurity. The changeset is minimal, so an update should be smooth.

Best regards,

Christian Folini, CRS Co-Lead

-- 
Had I been present at the creation, I would have given some useful
hints for the better ordering of the universe.
-- Alfonso the Wise, 1221 - 1284


_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/