More information about security issue - CVE 2024-1019

Ervin Hegedüs <[email protected]> Tue, 30 Jan 2024 17:34:26 +0100
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <CAJ2uXbfBsdtKiwCywi1HtEjBUcUKryoz3F3x6E-giXYXM=0G0w@mail.gmail.com>
--===============3963499138465583144==
Content-Type: multipart/alternative; boundary="0000000000000be89106102c587f"

--0000000000000be89106102c587f
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Dear all,

As you can see in my previous e-mail, the new OWASP ModSecurity team is
happy
to announce the release of ModSecurity / libModSecurity v3.0.12, the first
release under the new organization.

Version 3.0.12 fixes CVE 2024-1019, a security bug with HIGH severity on th=
e
ModSec 3 release line.

Please find the complete advisory and and detailed information at
https://owasp.org/www-project-modsecurity/tab_cves#cve-2024-1019-2024-01-30

The code of the release can be found at
https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.12

DigitalWave will publish pre-compiled binaries later tonight or tomorrow
throughout the day at https://modsecurity.digitalwave.hu. I also try to
upload the patched versions for Debian and Ubuntu systems.

We advise all ModSecurity 3 users to upgrade to 3.0.12. A workaround for
those stuck on lower versions is covered in the link shared above.

Best,

Christian Folini, Marc Stern and Ervin Heged=C3=BCs

--0000000000000be89106102c587f
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Dear all,<br><br>As you can see in my previous e-mail, the=
 new OWASP ModSecurity team is happy<br>to announce the release of ModSecur=
ity / libModSecurity v3.0.12, the first<br>release under the new organizati=
on.<br><br>Version 3.0.12 fixes CVE 2024-1019, a security bug with HIGH sev=
erity on the<br>ModSec 3 release line.<br><br>Please find the complete advi=
sory and and detailed information at<br><a href=3D"https://owasp.org/www-pr=
oject-modsecurity/tab_cves#cve-2024-1019-2024-01-30">https://owasp.org/www-=
project-modsecurity/tab_cves#cve-2024-1019-2024-01-30</a><br><br>The code o=
f the release can be found at<br><a href=3D"https://github.com/owasp-modsec=
urity/ModSecurity/releases/tag/v3.0.12">https://github.com/owasp-modsecurit=
y/ModSecurity/releases/tag/v3.0.12</a><br><br>DigitalWave will publish pre-=
compiled binaries later tonight or tomorrow<br>throughout the day at <a hre=
f=3D"https://modsecurity.digitalwave.hu">https://modsecurity.digitalwave.hu=
</a>. I also try to<br>upload the patched versions for Debian and Ubuntu sy=
stems.<br><br>We advise all ModSecurity 3 users to upgrade to 3.0.12. A wor=
karound for<br>those stuck on lower versions is covered in the link shared =
above.<br><br>Best,<br><br>Christian Folini, Marc Stern and Ervin Heged=C3=
=BCs</div>

--0000000000000be89106102c587f--


--===============3963499138465583144==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============3963499138465583144==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

--===============3963499138465583144==--