8000 Allow REPORT requests without Content-Type header in Nextcloud · Issue #1743 · coreruleset/coreruleset · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Allow REPORT requests without Content-Type header in Nextcloud #1743

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
CRS-migration-bot opened this issue May 13, 2020 · 0 comments
Closed

Comments

@CRS-migration-bot
Copy link

Issue for tracking original pull request created by user pyllyukko on date 2020-04-21 16:28:31.
Link to original PR: SpiderLabs/owasp-modsecurity-crs#1743.

HEAD is: fb32edd
BASE is: cf57fd5

Issue

When the file list in the iOS app is refreshed, it triggers Missing Content-Type Header with Request Body rule with a REPORT request to /remote.php/dav/files/<username>

Background

Sofware Version
CRS 3.2.0
ModSecurity 3.0.4
Nextcloud 18.0.3
Nextcloud iOS app 2.25.9.2

Fix

This PR disables rule 920340 with REPORT requests to /remote.php/dav/files/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant
0