Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package owasp-modsecurity-crs for 
openSUSE:Factory checked in at 2026-08-28 19:53:18
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/owasp-modsecurity-crs (Old)
 and      /work/SRC/openSUSE:Factory/.owasp-modsecurity-crs.new.1265 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "owasp-modsecurity-crs"

Fri Aug 28 19:53:18 2026 rev:14 rq:1374308 version:4.29.0

Changes:
--------
--- 
/work/SRC/openSUSE:Factory/owasp-modsecurity-crs/owasp-modsecurity-crs.changes  
    2026-06-01 18:09:49.864800092 +0200
+++ 
/work/SRC/openSUSE:Factory/.owasp-modsecurity-crs.new.1265/owasp-modsecurity-crs.changes
    2026-08-28 19:55:54.654863280 +0200
@@ -1,0 +2,54 @@
+Fri Aug 28 08:40:48 UTC 2026 - Petr Gajdos <[email protected]>
+
+- version update to 4.29.0
+  * Requires libmodsecurity v3.0.16 or later (Nginx/libmodsecurity v3)
+    due to XML attribute injection fix in rule 901181 depending on
+    ModSecurity#3589.
+  * Fully opting out of XML attribute inspection requires ModSecurity
+    v2 >= v2.9.14 (pending fix in ModSecurity#3591).
+  * Fixes CVE-2026-33691 (Whitespace padding bypass in file upload
+    extension checks) across PHP double-extensions (#4547), PHP upload
+    detection (#4546), and JSP file upload detection (#4548).
+  * Backport hardening for 4RI-250413 (JSON-encoded key/variable-assignment
+    noise handling across LDAP, RCE, generic, and SQL).
+  * Backport ReDoS Hardening: Remove exponential backtracking in PHP
+    function-call comment/whitespace (933160/933161) and PHP variable-
+    function noise (933180) suffixes.
+  * Add backslash-prefix evasion to shell command detection (rule 932) (#4599).
+  * Detect basic quote evasion attempts against known Unix commands (#4649).
+  * Detect the 'stat' command at Paranoia Level 2+ (PL-2+) (#4735).
+  * Expand web shells (v1) to detect fresh signatures for known PHP backdoors
+    (#4626).
+  * Allow optional 'json.' prefix in rule 932171 ARGS_NAMES (#4703).
+  * Require operator/quote after '!' to cut down SQL FPs (rule 942190) (#4704).
+  * Tighten SQL comment detection comma branch to cut down User-Agent/Referer
+    FPs (rule 942200) (#4665).
+  * Remove bypassable length bound on quoted/unary SQL literals (#4713).
+  * Fix response body FPs with "(inclusive)" and "must be a valid" (#4697)
+    and with "'> in all'" (#4736).
+  * Remove 'w' from Unix no-arguments command list (#4592).
+  * Require arguments for base64, lastlog, lastlogin in Unix rules (#4593).
+  * Restore node_modules coverage (rule 930120) (#4681).
+  * Backport SQL comma without whitespace FP fix, exclude 'pg' command from
+    PL1 Unix detection, fix parameter name FPs containing '.history' (930120),
+    and drop HTTP/0.9 GET support from request line validation (920100).
+- version update to 4.28.0
+  * Inspect XML attribute values across attack-detection rules 
(GHSA-6jp8-c2w2-x7wr).
+  * Remove catastrophic backtracking in unix-shell-evasion prefix
+    (GHSA-f5qm-3h4p-8qhg).
+  * Enable 'crs_validate_utf8_encoding' by default (#4647).
+  * Added detection for quote evasion (#3813).
+  * Detect ORM lookup operator injection (rule 934) (#4659).
+  * Detect uninitialized variable spacer in RCE evasion prefix (rule 932) 
(#4652).
+  * Create 941170.ra file (#4493).
+  * Update restricted-files.data to include NPM subdirectories without FPs 
(#4653).
+  * Remove exponential backtracking in comment suffix (933160/933161) (#4666),
+    CSS url(javascript) detection (941140) (#4670), and variable-function noise
+    suffix (933180) (#4669).
+  * Move rule 942390 to regex-assembly (#4011).
+  * Add default actions for phases 3-5 in crs-setup (#4675).
+  * Avoid excessive backtracking in rule 942522 (#4676).
+  * Hardening against 4RI-250413 (#4672).
+  * Fix FPs related to RESPONSE_BODY (#4684).
+
+-------------------------------------------------------------------

Old:
----
  coreruleset-4.27.0.tar.gz
  coreruleset-4.27.0.tar.gz.asc

New:
----
  coreruleset-4.29.0.tar.gz
  coreruleset-4.29.0.tar.gz.asc

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ owasp-modsecurity-crs.spec ++++++
--- /var/tmp/diff_new_pack.JMkRCB/_old  2026-08-28 19:55:55.685899327 +0200
+++ /var/tmp/diff_new_pack.JMkRCB/_new  2026-08-28 19:55:55.692899572 +0200
@@ -18,7 +18,7 @@
 
 
 Name:           owasp-modsecurity-crs
-Version:        4.27.0
+Version:        4.29.0
 Release:        0
 Summary:        OWASP ModSecurity Common Rule Set (CRS)
 License:        Apache-2.0

++++++ coreruleset-4.27.0.tar.gz -> coreruleset-4.29.0.tar.gz ++++++
++++ 17891 lines of diff (skipped)

Reply via email to