SpiderLabs / owasp-modsecurity-crs

OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)
https://modsecurity.org/crs
Apache License 2.0
2.44k stars 725 forks source link

XenForo: update exclusions #1739

Closed lifeforms closed 4 years ago

lifeforms commented 4 years ago

Running on live traffic produced some false positives, which are remedied with this update.

Added a few new endpoints, widened exclusions on some existing patterns, and fixed a bug in 9006160.

franbuehler commented 4 years ago

In the monthly chat meeting from May 4 we decided to merge this PR: https://github.com/SpiderLabs/owasp-modsecurity-crs/issues/1749#issuecomment-623634756