Announcing ModSecurity release 3.0.12

Ervin Hegedüs <[email protected]> Tue, 30 Jan 2024 17:26:13 +0100
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <CAJ2uXbd6Vh0KLJ+S=aB18KoM1OBd7Ybjb95coAsKQVPTCCCNrg@mail.gmail.com>
--===============6550047987621005275==
Content-Type: multipart/alternative; boundary="000000000000b59e2e06102c3ae4"

--000000000000b59e2e06102c3ae4
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Dear ModSecurity users,

ModSecurity is announcing the release of version 3.0.12.

This version includes a bug fixes, see the release notes:

=3D=3D%=3D=3D

Security impacting issue

    Change REQUEST_FILENAME and REQUEST_BASENAME behavior
    [Issue #3048 - @martinhsv, @theMiddleBlue, @theseion, @M4tteoP,
@airween]
    WAF bypass of the ModSecurity v3 release line for path-based payloads
by submitting a specially crafted request URL. For details, see CVE
2024-1019.

Enhancements and bug fixes

    Set the minimum security protocol version (TLSv1.2) for SecRemoteRules
    [Issue security/code-scanning/2 - @airween]

=3D=3D%=3D=3D

Additional information on the release, including the source (and
hashes/signatures), is available at:
https://github.com/SpiderLabs/ModSecurity/releases/tag/v3.0.12

Thanks to everybody who helped in this process: reporting issues, making
comments and suggestions, sending patches, etc.



Regards:

Christian Folini, Marc Stern and Ervin Heged=C3=BCs

--000000000000b59e2e06102c3ae4
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div>Dear ModSecurity users,<br></div><div><br></div><div>=
ModSecurity is announcing the release of version 3.0.12.</div><div><br></di=
v><div>This version includes a bug fixes, see the release notes:</div><div>=
<br></div><div>=3D=3D%=3D=3D<br></div><div><br></div><div>Security impactin=
g issue<br><br>=C2=A0 =C2=A0 Change REQUEST_FILENAME and REQUEST_BASENAME b=
ehavior<br>=C2=A0 =C2=A0 [Issue #3048 - @martinhsv, @theMiddleBlue, @thesei=
on, @M4tteoP, @airween]<br>=C2=A0 =C2=A0 WAF bypass of the ModSecurity v3 r=
elease line for path-based payloads by submitting a specially crafted reque=
st URL. For details, see CVE 2024-1019.<br><br>Enhancements and bug fixes<b=
r><br>=C2=A0 =C2=A0 Set the minimum security protocol version (TLSv1.2) for=
 SecRemoteRules<br>=C2=A0 =C2=A0 [Issue security/code-scanning/2 - @airween=
]</div><div><br></div><div>=3D=3D%=3D=3D</div><div><br></div><div>Additiona=
l information on the release, including the source (and hashes/signatures),=
 is available at: <a href=3D"https://github.com/SpiderLabs/ModSecurity/rele=
ases/tag/v3.0.12">https://github.com/SpiderLabs/ModSecurity/releases/tag/v3=
.0.12</a><br><br>Thanks to everybody who helped in this process: reporting =
issues, making comments and suggestions, sending patches, etc.</div><div><b=
r></div><div><br></div><div><br></div><div>Regards:</div><div><br></div><di=
v>Christian Folini, Marc Stern and Ervin Heged=C3=BCs </div><div><br></div>=
</div>

--000000000000b59e2e06102c3ae4--


--===============6550047987621005275==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============6550047987621005275==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

--===============6550047987621005275==--