owasp-modsecurity / owasp-modsecurity/ModSecurity
Transformation `hexDecode` should not allow badly encoded inputs, or documentation should be updated
Nobody has claimed this yet.
- Dominant language
- C++
- Stars
- 9.8k
- Forks
- 1.8k
- Avg merge
- 2h 46m
- Merged PRs (30d)
- 1
Description
Describe the bug
This comes from this discussion: https://github.com/corazawaf/coraza/issues/1253.
Technically, there is one test that accepts a string that could not be generated by hexEncode.
👉 Is this the expected behavior?
I think accepting a broken input is just prone to more errors. Don't know how this affects a possible chain of transformations.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the hexDecode transformation and the existing test mentioned in the report; verify whether the accepted input could be produced by hexEncode and how chained transformations affect it. Done means establishing the intended behavior for malformed input and either correcting the behavior or updating the documentation accordingly.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- cpp
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100