Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
97d8c1e101 |
@@ -232,7 +232,9 @@ in `bin/state` unless `SWWAF_STATE_DIR` is set, and the default rule file of
|
||||
command names (932260), so that a file such as `.gitignore` or a branch
|
||||
such as `docker-build` gets through there. So does what only these rules
|
||||
refuse, such as `|cat /etc/passwd`; path traversal and SQL injection are
|
||||
still refused there.
|
||||
still refused there. These names, and `redirect_uri` above, are matched
|
||||
without regard to case, as Coraza matches them, so `Path` or `PATH` is
|
||||
treated as `path`.
|
||||
- The cookies `gitea_flash` and `redirect_to` are not read, and `Referer` is
|
||||
not checked for a Unix command given without arguments (932340) or for
|
||||
Java starting a process (944110); it is checked by every other rule.
|
||||
|
||||
@@ -618,10 +618,12 @@ The settings, by group:
|
||||
`|cat /etc/passwd`, `wget http://…` and `nc -e /bin/sh …`, and
|
||||
`file:///etc/passwd`, pass as well. Path traversal (`../`), SQL and
|
||||
script injection and PHP, Java and Node.js code are still refused
|
||||
there, and every other parameter keeps all three rules. An app that
|
||||
uses one of these parameters as a file on the server, or passes it to
|
||||
a shell, gets no help from the three rules there (see "Risks the
|
||||
design has to handle").
|
||||
there, and every other parameter keeps all three rules. These names,
|
||||
and `redirect_uri` in the change before, are matched without regard to
|
||||
case, as Coraza matches them, so `Path` or `PATH` is treated as
|
||||
`path`. An app that uses one of these parameters as a file on the
|
||||
server, or passes it to a shell, gets no help from the three rules
|
||||
there (see "Risks the design has to handle").
|
||||
- The Core Rule Set reads the request without the `gitea_flash` and
|
||||
`redirect_to` cookies, and does not check `Referer` for a Unix command
|
||||
given without arguments (932340) or for Java starting a process
|
||||
|
||||
+2
-1
@@ -56,7 +56,8 @@ SecAction "id:900250,phase:1,pass,nolog,\
|
||||
Include @owasp_crs/REQUEST-*.conf
|
||||
|
||||
# The third: redirect_uri is not checked for a URL naming an IP address or
|
||||
# localhost.
|
||||
# localhost. Coraza matches a parameter name here, and in the fourth,
|
||||
# without regard to case.
|
||||
SecRuleUpdateTargetById 931100 "!ARGS:redirect_uri"
|
||||
SecRuleUpdateTargetById 934110 "!ARGS:redirect_uri"
|
||||
|
||||
|
||||
@@ -233,6 +233,16 @@ func TestParametersGiteaSendsNamesInSkipTheListsOfFilesPathsAndCommands(t *testi
|
||||
wantResult(t, crs, get("/?path=1'%20OR%20'1'='1"), matched(942100))
|
||||
}
|
||||
|
||||
func TestParameterNamesAreMatchedWithoutRegardToCase(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
crs := atDefaults(t)
|
||||
|
||||
wantChange(t, crs, get("/?Path=.gitignore"), get("/?q=.gitignore"), matched(930120))
|
||||
wantChange(t, crs, get("/?REDIRECT_URI=http://127.0.0.1:52341/"),
|
||||
get("/?next=http://127.0.0.1:52341/"), matched(931100, 934110))
|
||||
}
|
||||
|
||||
func TestCookiesGiteaFlashAndRedirectToAreNotRead(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user