github owasp-modsecurity/ModSecurity v3.0.11

latest release: v3.0.12
4 months ago

Security impacting issue

  • Add WRDE_NOCMD to wordexp call
    [Issue #3024 - @sahruldotid, @martinhsv ]
    Note: Although this issue ostensibly allows for specially-crafted SecRule content to execute OS command-line commands when the rules are loaded, this is unlikely to be a serious issue in most deployments. A malicious actor who has access to modify the ModSecurity configuration of an installation can cause severe effects in a multitude of other ways.

New feature

Enhancements and bug fixes

Don't miss a new ModSecurity release

NewReleases is sending notifications on new releases.