Overview

Request 1107853 revoked

- Version 3.3.5.
* This is the OWASP ModSecurity Core Rule Set version 3.3.5.
* Important changes:
- Backport fix for CVE-2023-38199 from CRS v4 via new rule 920620 (Andrea Menin, Felipe Zipitría)
* Fixes:
- Fix paranoia level-related scoring issue in rule 921422 (Walter Hop)
- Move auditLogParts actions to the end of chained rules where used (Ervin Hegedus)
* Chore:
- Clean up redundant paranoia level tags (Ervin Hegedus)
- Clean up YAML test files to support go-ftw testing framework (Felipe Zipitría)
- Move testing framework from ftw to go-ftw (Felipe Zipitría)
- Version 3.3.4.
* Important Notice: From CRS 3.2.2, 3.3.3 and up, ModSecurity 2.9.6 or 3.0.8 (or versions with backported patches) are required due to the addition of new protections. We recommend upgrading your ModSecurity as soon as possible. If your ModSecurity is too old, your webserver will refuse to start with an Unknown variable: &MULTIPART_PART_HEADERS error. If you are in trouble, you can temporarily delete file rules/REQUEST-922-MULTIPART-ATTACK.conf as a workaround and get your server up, however, you will be missing some protections. Therefore we recommend to upgrade ModSecurity before deploying this release.

- use system apache rpm macros
- sort conf file entries to fix build-compare (boo#1041090)
- Update to version 2.2.9
* Updated the /util directory structure
* fix 950901 - word boundary added
* modsecurity_35_bad_robots.data - gecko/25 blocks Firefox Android
https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/157
- Fix SuSE > SUSE spelling
- Use download Url as source
- Do not explicitely depend on apache2; apache2-mod_security2
depends on it
- Remove redundant %clean section
- Do not copy INSTALL file into the package
- ChangeLog has been replaced with CHANGES in upstream
- Raised version to 2.2.6.
* Resolves bnc#779076
* Resolves CORERULES-87
- Package modification for factory submission:
* Changed services to localonly mode
* Added copyright information to spec file
- Added README.SuSE
- Initial package version 2.2.5

Request History
Alessandro de Oliveira Faria's avatar

cabelo created request

- Version 3.3.5.
* This is the OWASP ModSecurity Core Rule Set version 3.3.5.
* Important changes:
- Backport fix for CVE-2023-38199 from CRS v4 via new rule 920620 (Andrea Menin, Felipe Zipitría)
* Fixes:
- Fix paranoia level-related scoring issue in rule 921422 (Walter Hop)
- Move auditLogParts actions to the end of chained rules where used (Ervin Hegedus)
* Chore:
- Clean up redundant paranoia level tags (Ervin Hegedus)
- Clean up YAML test files to support go-ftw testing framework (Felipe Zipitría)
- Move testing framework from ftw to go-ftw (Felipe Zipitría)
- Version 3.3.4.
* Important Notice: From CRS 3.2.2, 3.3.3 and up, ModSecurity 2.9.6 or 3.0.8 (or versions with backported patches) are required due to the addition of new protections. We recommend upgrading your ModSecurity as soon as possible. If your ModSecurity is too old, your webserver will refuse to start with an Unknown variable: &MULTIPART_PART_HEADERS error. If you are in trouble, you can temporarily delete file rules/REQUEST-922-MULTIPART-ATTACK.conf as a workaround and get your server up, however, you will be missing some protections. Therefore we recommend to upgrade ModSecurity before deploying this release.

- use system apache rpm macros
- sort conf file entries to fix build-compare (boo#1041090)
- Update to version 2.2.9
* Updated the /util directory structure
* fix 950901 - word boundary added
* modsecurity_35_bad_robots.data - gecko/25 blocks Firefox Android
https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/157
- Fix SuSE > SUSE spelling
- Use download Url as source
- Do not explicitely depend on apache2; apache2-mod_security2
depends on it
- Remove redundant %clean section
- Do not copy INSTALL file into the package
- ChangeLog has been replaced with CHANGES in upstream
- Raised version to 2.2.6.
* Resolves bnc#779076
* Resolves CORERULES-87
- Package modification for factory submission:
* Changed services to localonly mode
* Added copyright information to spec file
- Added README.SuSE
- Initial package version 2.2.5


Saul Goodman's avatar

licensedigger accepted review

ok


Factory Auto's avatar

factory-auto reopened review

Source URLs are not valid. Try `osc service runall download_files`.
owasp-modsecurity-crs-3.3.5.tar.xz /home/go/co/1107853/owasp-modsecurity-crs/owasp-modsecurity-crs-3.3.5.tar.xz differ: byte 1, line 1
ERROR: download_files is configured to fail when the upstream file is different than the committed file... this is the case!


Ana Guerrero's avatar

anag+factory declined review

sr#1105927 has same source and is already staged


Ana Guerrero's avatar

anag+factory declined request

sr#1105927 has same source and is already staged


Alessandro de Oliveira Faria's avatar

cabelo revoked request

openSUSE Build Service is sponsored by