owasp-modsecurity / owasp-modsecurity/ModSecurity

Variable needed : REQUEST_HAS_BODY to avoid content-type evasion

Open
#3,466 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
C++
Stars
9.8k
Forks
1.8k
Avg merge
2h 46m
Merged PRs (30d)
1

Description

Hello,

This issue followed this PR : https://github.com/coreruleset/coreruleset/pull/4347 and this comment : https://github.com/coreruleset/coreruleset/pull/4347#issuecomment-3556322624

`Since we cannot rely on REQUEST_BODY (and therefore not on REQUEST_BODY_LENGTH, which depends on REQUEST_BODY) for this use case, we are missing a REQUEST_HAS_BODY variable.

Would it be difficult to implement?

Given that you do not want to use STREAM_INPUT_BODY in PL1 (which I understand), I don’t see any other solution to handle this glaring security gap.`

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading PR 4347 and its linked comment, then trace how REQUEST_BODY and REQUEST_BODY_LENGTH are provided and how STREAM_INPUT_BODY is handled at PL1. Done means determining whether a REQUEST_HAS_BODY variable can be exposed to close the described content-type evasion gap, with behavior covered by the project's relevant tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
cpp
Domain
security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.