owasp-modsecurity / owasp-modsecurity/ModSecurity

Transformation `hexDecode` should not allow badly encoded inputs, or documentation should be updated

Open
#3,325 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

2.x 3.x
Dominant language
C++
Stars
9.8k
Forks
1.8k
Avg merge
2h 46m
Merged PRs (30d)
1

Description

Describe the bug

This comes from this discussion: https://github.com/corazawaf/coraza/issues/1253.

Technically, there is one test that accepts a string that could not be generated by hexEncode.

👉 Is this the expected behavior?

I think accepting a broken input is just prone to more errors. Don't know how this affects a possible chain of transformations.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the hexDecode transformation and the existing test mentioned in the report; verify whether the accepted input could be produced by hexEncode and how chained transformations affect it. Done means establishing the intended behavior for malformed input and either correcting the behavior or updating the documentation accordingly.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.