OWASP ModSecurity Core Rule Set V3.0 breaks after every update

Operating System & Version
CloudLinux 7.7
cPanel & WHM Version
v84.0.21

artidens

Registered
Apr 21, 2017
2
0
1
Finland
cPanel Access Level
Root Administrator
When I run "/usr/local/cpanel/scripts/modsec_vendor update OWASP3" I get the following errors:

Code:
The system failed to update the vendor from the URL http://httpupdate.cpanel.net/modsecurity-rules/meta_OWASP3.yaml
warn [modsec_vendor] The system failed to update the vendor from the URL http://httpupdate.cpanel.net/modsecurity-rules/meta_OWASP3.yaml
Also, Apache fails to restart because of missing OWASP3 rules:

Code:
Syntax error on line 259 of /etc/apache2/conf/httpd.conf: Syntax error on line 32 of /etc/apache2/conf.d/modsec2.conf:
Syntax error on line 29 of /etc/apache2/conf.d/modsec/modsec2.cpanel.conf:
Could not open configuration file /etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-901-INITIALIZATION.conf: No such file or directory
The folder /etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules becomes empty. To fix this, I must go to WHM -> Security Center -> ModSecurity Vendors and click "Install" on the OWASP3 as it has become uninstalled. This happens basically every night after the WHM update so I have to manually fix it to get Apache running again. Any help?
 

cPanelLauren

Product Owner
Staff member
Nov 14, 2017
13,297
1,251
313
Houston
Can you please open a ticket using the link in my signature? Once open please reply with the Ticket ID here so that we can update this thread with the resolution once the ticket is resolved.


Thanks!