owasp-modsecurity / owasp-modsecurity/ModSecurity

PATCH method dies with mod security with nginx configured as proxy/ingress

Open
#2,341 22 comments 1 reaction 0 assignees View on GitHub

Nobody has claimed this yet.

3.x Platform - Nginx workaround available
Dominant language
C++
Stars
9.8k
Forks
1.8k
Avg merge
2h 46m
Merged PRs (30d)
1

Description

Version info:

version: libmodsecurity.so.3.0.3

name: nginx-ingress
repository: https://kubernetes-charts.storage.googleapis.com
version: 1.33.5
kubectl version
Server Version: version.Info{Major:"1", Minor:"16", GitVersion:"v1.16.9", GitCommit:"a17149e1a189050796ced469dbd78d380f2ed5ef", GitTreeState:"clean", BuildDate:"2020-04-16T23:15:50Z", GoVersion:"go1.13.9", Compiler:"gc", Platform:"linux/amd64"}

===> cross-post from https://github.com/kubernetes/ingress-nginx/issues/5723

Summary Observations:
PATCH method with JSON request body sent to ingress receives no response bytes on connection and connection is left open.

Connection is closed only when NGINX ingress is bounced due to server reload (on change of ConfigMap, pod deletion ... etc)

when Debug logging is enabled with
SecDebugLog /dev/stdout
SecDebugLogLevel 4

the debug log shows that phase 1 of the Modsecurity (a) recognized the "application/json", and that (b) phase 2 assigned the JSON attributes into ARGS for subsequent scanning.

** Changing from "DetectOnly" to rule enforcement does not change the behavior. Adding the CRS ruleset does not change the behavior.

** POST and PUT methods work without hanging the connection
** PATCH method works correctly when enable-modsecurity: "false"

====================================

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce a PATCH request with an application/json body through the nginx-ingress path using the listed ModSecurity and Kubernetes versions. Enable SecDebugLog /dev/stdout and SecDebugLogLevel 4, then compare the ModSecurity phases with POST and PUT; done means PATCH returns a response and does not leave the connection open.

Written by the indexing model from the issue text.

Assessment

Tech stack
kubernetes, nginx
Domain
networking, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.