Announcing ModSecurity release 2.9.8
Ervin Hegedüs <[email protected]> Tue, 3 Sep 2024 16:38:06 +0200
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <[email protected]> |
--jramk63z7rgrmp7d
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
Dear ModSecurity users,
ModSecurity is announcing the release of version 2.9.8.
This version includes a bug fixes and new features.
See CHANGELOG[1] and new blog post[2].
Additional information on the release, including the source (and
hashes/signatures), is available at:
https://github.com/SpiderLabs/ModSecurity/releases/tag/v2.9.8
Thanks to everybody who helped in this process: reporting issues, making
comments and suggestions, sending patches, etc.
Regards:
Marc Stern and Ervin Hegedüs
1: https://github.com/owasp-modsecurity/ModSecurity/blob/v2.9.8/CHANGES
2: https://modsecurity.org/20240903/new-versions-2024-september/
--jramk63z7rgrmp7d
Content-Type: text/html; charset=UTF-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
<div dir=3D"ltr"><pre>Dear ModSecurity users,
ModSecurity is announcing the release of version 3.0.12.
This version includes a bug fixes, see the release notes:
=3D=3D%=3D=3D
Security impacting issue
Change REQUEST_FILENAME and REQUEST_BASENAME behavior
[Issue #3048 - @martinhsv, @theMiddleBlue, @theseion, @M4tteoP,
@airween]
WAF bypass of the ModSecurity v3 release line for path-based payloads
by submitting a specially crafted request URL. For details, see CVE
2024-1019.
Enhancements and bug fixes
Set the minimum security protocol version (TLSv1.2) for SecRemoteRules
[Issue security/code-scanning/2 - @airween]
=3D=3D%=3D=3D
Additional information on the release, including the source (and
hashes/signatures), is available at:
<a href=3D"https://github.com/SpiderLabs/ModSecurity/releases/tag/v3.0.12" =
rel=3D"nofollow">https://github.com/SpiderLabs/ModSecurity/releases/tag/v3.=
0.12</a>
Thanks to everybody who helped in this process: reporting issues, making
comments and suggestions, sending patches, etc.
Regards:
Christian Folini, Marc Stern and Ervin Heged=C3=BCs</pre></div>
--jramk63z7rgrmp7d
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
--jramk63z7rgrmp7d
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
_______________________________________________
mod-security-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/mod-security-users
Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs:
http://www.modsecurity.org/projects/commercial/rules/
http://www.modsecurity.org/projects/commercial/support/
--jramk63z7rgrmp7d--