github owasp-modsecurity/ModSecurity v2.9.4

latest releases: v3.0.13, v2.9.8, v3.0.12...
3 years ago

Enhancements

Bug fixes

  • Store temporaries in the request pool for regexes compiled per-request.
    [Issue #890, #2049 - @lightsey]
  • Fix other usage of the global pool for request temporaries in re_operators.c
    [Issue #890, #2049 - @lightsey]
  • Adds a sanity check before use ctl:ruleRemoveTargetById and ctl:ruleRemoveTargetByMsg.
    [Issue #2033 - @studersi]
  • Fix the order of error_msg validation
    [Issue #2128 - @marcstern, @zimmerle]
  • When the input filter finishes, check whether we returned data
    [Issue #2091, #2092 - @rainerjung]
  • fix: care non-null terminated chunk data
    [Issue #2097 - @orisano]
  • Fix for apr_global_mutex_create() crashes with mod_security
    [Issue #1957 - @blappm]
  • Fix inet addr handling on 64 bit big endian systems
    [Issue #1980 - @zimmerle, @airween]

Notes

  • Windows installer no longer includes OWASP CRS.

Don't miss a new ModSecurity release

NewReleases is sending notifications on new releases.