Skip to content

v3.0.11

Compare
Choose a tag to compare
@martinhsv martinhsv released this 06 Dec 20:01
· 306 commits to v3/master since this release
v3.0.11
bbde938

Security impacting issue

  • Add WRDE_NOCMD to wordexp call
    [Issue #3024 - @sahruldotid, @martinhsv ]
    Note: Although this issue ostensibly allows for specially-crafted SecRule content to execute OS command-line commands when the rules are loaded, this is unlikely to be a serious issue in most deployments. A malicious actor who has access to modify the ModSecurity configuration of an installation can cause severe effects in a multitude of other ways.

New feature

Enhancements and bug fixes