12 Commits

Author SHA1 Message Date
starlet-dx
2dd80b7b0e Fix HTTP service startup failure
(cherry picked from commit c31b32e808518d2eed01205baaa17f75c8d6dab2)
2024-05-07 09:45:56 +08:00
starlet-dx
0820ca61ca Fix CVE-2022-48279
(cherry picked from commit af16f81ec3f6dc0cb2ce54c4e50105a6d801efd9)
2024-03-26 11:19:08 +08:00
yaoguangzhong
b0d3ff6532 backport allow no-key, single-value JSON body
From Author: Martin Vierula <martin.vierula@trustwave.com>
From commit 4a98032b7f827c4edd2514ce2af29222bb2ba289
Signed-off-by: Guangzhong Yao <yaoguangzhong@xfusion.com>
2023-01-09 16:11:13 +08:00
yaoguangzhong
47f5c296d3 backport set SecStatusEngine Off in modsecurity.conf-recommended
From author: Martin Vierula <martin.vierula@trustwave.com>
commit 733427197e2fe4fabcbb0f43bd1e636ef923a6b4
Signed-off-by: Guangzhong Yao <yaoguangzhong@xfusion.com>
2023-01-07 17:21:12 +08:00
yaoguangzhong
5e29074404 backport fix memory leak that occurs on JSON parsing error
From Author: Martin Vierula <martin.vierula@trustwave.com>
commit c6582df2e5e3a92ba4b90e2a6cfaeb89f61bcadf
Signed-off-by: Guangzhong Yao <yaoguangzhong@xfusion.com>
2023-01-07 15:07:10 +08:00
yaoguangzhong
4312bdb7b5 backport Add SecRequestBodyJsonDepthLimit to modsecurity.conf-recommended
From Author: Martin Vierula <martin.vierula@trustwave.com>
commit 60be05914ce3b23bc126cfa61face7b75650448f
Signed-off-by: Guangzhong Yao <yaoguangzhong@xfusion.com>
2023-01-07 11:24:21 +08:00
yaoguangzhong
0473055543 backport properly cleanup XML parser contexts upon completion
Signed-off-by: Guangzhong Yao <yaoguangzhong@xfusion.com>
2023-01-06 20:08:36 +08:00
yaoguangzhong
e56ed34634 backport use uid if user name is not available
Signed-off-by: Guangzhong Yao <yaoguangzhong@xfusion.com>
2023-01-06 17:08:23 +08:00
xu_lei_123
8d6e309d17 fix date error on 2.9.5-2 2022-12-24 13:04:45 +08:00
lyn1001
3dde482aac Fix build fail with lua 5.4.3 2022-01-07 09:55:25 +08:00
starlet-dx
5ac4336fa2 Upgrademod_securityto 2.9.5forfixCVE-2021-42717
(cherry picked from commit 5e6ab20f5effa1b0e79d064b8dd6f73ed3ec0f36)
2021-12-14 16:50:27 +08:00
fun_yang
790462571f package init 2020-02-14 15:43:49 +08:00