owasp-modsecurity / owasp-modsecurity/ModSecurity

Best solution/workaround sanitise modsecurity v3

Open
#3,163 2 comments 2 reactions 1 assignee View on GitHub

@airween is already working on this.

Since May 31, 2024.

3.x duplicate libmodsec - missing features
Dominant language
C++
Stars
9.8k
Forks
1.8k
Avg merge
2h 46m
Merged PRs (30d)
1

Description

** Description of the bug **
On modsecurity v3 and OWASP CRS 4.x there are a lot of password rule matching and we notice the password printed into the modsecurity audit logs. We also noticed that sanitiseArg is not supported on v3 branch.

Do you plan to support in the near future this important function?

Do you aware of a better method than removing the printed part of values ​​via SecAuditLogParts?

The found some issue related to the sanitise implementation on v3 branch like:

#1132
#1898

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.