Announcing ModSecurity release 2.9.8

Ervin Hegedüs <[email protected]> Tue, 3 Sep 2024 16:38:06 +0200
Newsgroups gmane.comp.apache.mod-security.user
Message-ID <[email protected]>
--jramk63z7rgrmp7d
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: 8bit

Dear ModSecurity users,

ModSecurity is announcing the release of version 2.9.8.

This version includes a bug fixes and new features.

See CHANGELOG[1] and new blog post[2].

Additional information on the release, including the source (and
hashes/signatures), is available at:
https://github.com/SpiderLabs/ModSecurity/releases/tag/v2.9.8

Thanks to everybody who helped in this process: reporting issues, making
comments and suggestions, sending patches, etc.



Regards:

Marc Stern and Ervin Hegedüs


1: https://github.com/owasp-modsecurity/ModSecurity/blob/v2.9.8/CHANGES
2: https://modsecurity.org/20240903/new-versions-2024-september/


--jramk63z7rgrmp7d
Content-Type: text/html; charset=UTF-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><pre>Dear ModSecurity users,

ModSecurity is announcing the release of version 3.0.12.

This version includes a bug fixes, see the release notes:

=3D=3D%=3D=3D

Security impacting issue

    Change REQUEST_FILENAME and REQUEST_BASENAME behavior
    [Issue #3048 - @martinhsv, @theMiddleBlue, @theseion, @M4tteoP,
@airween]
    WAF bypass of the ModSecurity v3 release line for path-based payloads
by submitting a specially crafted request URL. For details, see CVE
2024-1019.

Enhancements and bug fixes

    Set the minimum security protocol version (TLSv1.2) for SecRemoteRules
    [Issue security/code-scanning/2 - @airween]

=3D=3D%=3D=3D

Additional information on the release, including the source (and
hashes/signatures), is available at:
<a href=3D"https://github.com/SpiderLabs/ModSecurity/releases/tag/v3.0.12" =
rel=3D"nofollow">https://github.com/SpiderLabs/ModSecurity/releases/tag/v3.=
0.12</a>

Thanks to everybody who helped in this process: reporting issues, making
comments and suggestions, sending patches, etc.



Regards:

Christian Folini, Marc Stern and Ervin Heged=C3=BCs</pre></div>

--jramk63z7rgrmp7d
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--jramk63z7rgrmp7d
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/

--jramk63z7rgrmp7d--