You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Issue for tracking original pull request created by user csjperon on date 2016-09-15 14:31:33.
Link to original PR: SpiderLabs/owasp-modsecurity-crs#578.
Add the urlDecodeUni transform operation to rules which inspect the
ARGS/ARGS_NAMES collections, which do not currently call urlDecodeUni
This operation should be here. Some rules were written under the assumption
that Apache/Nginx will automatically decode these collections prior to
entering Modsecurity.
This change shouldn't impact the rule quality, but will introduce additional decoding overhead
I am creating this PR to start the discussion
Thoughts?
The text was updated successfully, but these errors were encountered:
Issue for tracking original pull request created by user csjperon on date 2016-09-15 14:31:33.
Link to original PR: SpiderLabs/owasp-modsecurity-crs#578.
HEAD is: 73805dc
BASE is: 2396428
ARGS/ARGS_NAMES collections, which do not currently call urlDecodeUni
that Apache/Nginx will automatically decode these collections prior to
entering Modsecurity.
I am creating this PR to start the discussion
Thoughts?
The text was updated successfully, but these errors were encountered: