Facebook Twitter Instagram
    Goobuntu
    • Home
    • Linux
    • Windows
    • Mobile
    • News
    Goobuntu
    Home»News»OWASP ModSecurity Core Rule 3.3.5 Released

    OWASP ModSecurity Core Rule 3.3.5 Released

    0
    By Goobuntu on August 5, 2023 News
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The CRS v3.3.5 release has been announced by the OWASP ModSecurity Core Rule Set (CRS) team.

    The OWASP ModSecurity Core Rule Set (CRS) is a set of general attack detection rules that may be used with ModSecurity or other compatible web application firewalls.

    The CRS seeks to guard online applications against a variety of assaults, including the OWASP Top Ten, while producing the few false alarms as possible.

    The CRS offers defense against numerous popular attack types, such as SQL Injection, Cross Site Scripting, Local File Inclusion, and others.

    On March 24, 2023, the ModSecurity project first raised this vulnerability to the attention of the CRS project.

    Multiple HTTP “Content-Type” header fields are not detected by the OWASP ModSecurity Core Rule Set (CRS) v3.3.4.

    Because of this, on some platforms, a CRS installation may interpret an HTTP request body differently (as a result of the differing Content-Type) than a backend web application would.

    The company later determined that the CRS reference platform (ModSecurity 2.9.x on Apache 2.4) was unaffected.

    To resolve this vulnerability, CRS 3.3.5 has just been released.

    “This is a security release which fixes the recently announced CVE-2023-38199, whereby it is possible to cause an impedance mismatch on some platforms running CRS v3.3.4 and earlier by submitting a request with multiple Content-Type headers”, the Core Rule Set development team said in its advisory.

    Other Changes and Improvements in CRS v3.3.5 Release

    • Fix paranoia level-related scoring issue in rule 921422 (Walter Hop)
    • Move auditLogParts actions to the end of chained rules where used (Ervin Hegedus)
    • Clean up redundant paranoia-level tags (Ervin Hegedus)
    • Clean up YAML test files to support go-ftw testing framework (Felipe Zipitría)
    • Move testing framework from ftw to go-ftw (Felipe Zipitría)
    • Update sponsors list and copyright notices (Felipe Zipitría)

    Stay up-to-date with the latest Cyber Security News; follow us on GoogleNews, Linkedin, Twitter, and Facebook.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

    Related Posts

    Forever 21 Systems Hacked: 500,000+ Users Affected

    September 1, 2023

    Hackers Exploit Openfire Vulnerability To Deploy Kinsing Malware

    September 1, 2023

    BadBazaar Malware Attacking Users Via Weaponized Apps

    September 1, 2023

    Leave A Reply Cancel Reply

    Popular Posts
    Forever 21 Systems Hacked: 500,000+ Users Affected
    By GoobuntuSeptember 1, 20230
    How to Fix the Action Center Not Opening in Windows
    By GoobuntuSeptember 1, 20230
    Hackers Exploit Openfire Vulnerability To Deploy Kinsing Malware
    By GoobuntuSeptember 1, 20230
    BadBazaar Malware Attacking Users Via Weaponized Apps
    By GoobuntuSeptember 1, 20230
    © 2023 Goobuntu. All Rights Reserved Goobuntu.
    • Contact Us
    • Privacy Policy
    • DMCA
    • Sitemap

    Type above and press Enter to search. Press Esc to cancel.