owasp-modsecurity / owasp-modsecurity/ModSecurity
sanitiseMatchedBytes only sanitizes the first match
Open
@victorhora is already working on this.
Since May 20, 2017.
bug
enhancement
Platform - Apache
Platform - IIS
Platform - Java
Platform - Nginx
Platform - Standalone
TBF by libmodsec
- Dominant language
- C++
- Stars
- 9.8k
- Forks
- 1.8k
- Avg merge
- 2h 46m
- Merged PRs (30d)
- 1
Description
Rules that include a regular expression that is matched multiple times within the target variable (not multiple capture groups) with an action to capture and sanitiseMatchedBytes will only sanitize the first match. Subsequent matches within the target variable remain un-sanitized. It would be useful if all matches could be sanitized.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.