X-Post: CRS version 4.0.0 is out

Christian Folini <[email protected]> Wed, 14 Feb 2024 22:08:14 +0100
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <Zc0rvql/vPETZxSV@leander>
Dear ModSecurity users,

Let CRS 4 be your valentine!

The OWASP CRS team is proud to announce the release of CRS 4.0.

* https://github.com/coreruleset/coreruleset/releases/tag/v4.0.0

The release brings some 500 changes including the new plugin architecture.

More important updates:

* Early-Blocking option
* Over 500 individual rule bypasses closed following a big Bug Bounty project
* New web shell detection
* Full RE2/Hyperscan compatibility for better performance
* Support for HTTP/3
* More granular reporting options

Please read the detailed blog post coming with this release at

* https://coreruleset.org/20240214/let-crs-4-be-your-valentine/

or the full CHANGES file at 

* https://github.com/coreruleset/coreruleset/blob/v4.0/dev/CHANGES.md

With the best regards,

Christian Folini on behalf of the OWASP CRS team

-- 
The purpose of computing is insight not numbers.
-- Richard W. Hamming


_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/