More information about security issue - CVE 2024-1019
Ervin Hegedüs <[email protected]> Tue, 30 Jan 2024 17:34:26 +0100
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <CAJ2uXbfBsdtKiwCywi1HtEjBUcUKryoz3F3x6E-giXYXM=0G0w@mail.gmail.com> |
--===============3963499138465583144== Content-Type: multipart/alternative; boundary="0000000000000be89106102c587f" --0000000000000be89106102c587f Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Dear all, As you can see in my previous e-mail, the new OWASP ModSecurity team is happy to announce the release of ModSecurity / libModSecurity v3.0.12, the first release under the new organization. Version 3.0.12 fixes CVE 2024-1019, a security bug with HIGH severity on th= e ModSec 3 release line. Please find the complete advisory and and detailed information at https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30 The code of the release can be found at https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.12 DigitalWave will publish pre-compiled binaries later tonight or tomorrow throughout the day at https://modsecurity.digitalwave.hu. I also try to upload the patched versions for Debian and Ubuntu systems. We advise all ModSecurity 3 users to upgrade to 3.0.12. A workaround for those stuck on lower versions is covered in the link shared above. Best, Christian Folini, Marc Stern and Ervin Heged=C3=BCs --0000000000000be89106102c587f Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Dear all,<br><br>As you can see in my previous e-mail, the= new OWASP ModSecurity team is happy<br>to announce the release of ModSecur= ity / libModSecurity v3.0.12, the first<br>release under the new organizati= on.<br><br>Version 3.0.12 fixes CVE 2024-1019, a security bug with HIGH sev= erity on the<br>ModSec 3 release line.<br><br>Please find the complete advi= sory and and detailed information at<br><a href=3D"https://owasp.org/www-pr= oject-modsecurity/tab_cves#cve-2024-1019-2024-01-30">https://owasp.org/www-= project-modsecurity/tab_cves#cve-2024-1019-2024-01-30</a><br><br>The code o= f the release can be found at<br><a href=3D"https://github.com/owasp-modsec= urity/ModSecurity/releases/tag/v3.0.12">https://github.com/owasp-modsecurit= y/ModSecurity/releases/tag/v3.0.12</a><br><br>DigitalWave will publish pre-= compiled binaries later tonight or tomorrow<br>throughout the day at <a hre= f=3D"https://modsecurity.digitalwave.hu">https://modsecurity.digitalwave.hu= </a>. I also try to<br>upload the patched versions for Debian and Ubuntu sy= stems.<br><br>We advise all ModSecurity 3 users to upgrade to 3.0.12. A wor= karound for<br>those stuck on lower versions is covered in the link shared = above.<br><br>Best,<br><br>Christian Folini, Marc Stern and Ervin Heged=C3= =BCs</div> --0000000000000be89106102c587f-- --===============3963499138465583144== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============3963499138465583144== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/ --===============3963499138465583144==--