OWASP ModSecurity Core Rule Set 3.3.5 [Security Fix]

ciao70

Well-Known Member
Nov 3, 2006
151
34
178
Hello,

The OWASP ModSecurity Core Rule Set (CRS) team is pleased to announce the release of CRS v3.3.5.


This is a security release which fixes the recently announced CVE-2023-38199, whereby it is possible to cause an impedance mismatch on some platforms running CRS v3.3.4 and earlier by submitting a request with multiple Content-Type headers.


Fix coming via easy apache

 
Last edited by a moderator:
  • Like
Reactions: cPRex