coreruleset.org/20240829/crs-versions-4.6.0-and-3.3.6-have-been-released

Preview meta tags from the coreruleset.org website.

Linked Hostnames

8

Thumbnail

Search Engine Appearance

Google

https://coreruleset.org/20240829/crs-versions-4.6.0-and-3.3.6-have-been-released

CRS versions 4.6.0 and 3.3.6 have been released

We have recently released version 4.6.0 for CRS 4, fixing a serious problem. As this problem affects CRS 3 as well, we also did a backport release for v3. …



Bing

CRS versions 4.6.0 and 3.3.6 have been released

https://coreruleset.org/20240829/crs-versions-4.6.0-and-3.3.6-have-been-released

We have recently released version 4.6.0 for CRS 4, fixing a serious problem. As this problem affects CRS 3 as well, we also did a backport release for v3. …



DuckDuckGo

https://coreruleset.org/20240829/crs-versions-4.6.0-and-3.3.6-have-been-released

CRS versions 4.6.0 and 3.3.6 have been released

We have recently released version 4.6.0 for CRS 4, fixing a serious problem. As this problem affects CRS 3 as well, we also did a backport release for v3. …

  • General Meta Tags

    10
    • title
      CRS versions 4.6.0 and 3.3.6 have been released | CRS Project
    • charset
      utf-8
    • viewport
      width=device-width,initial-scale=1
    • Content-Security-Policy
      upgrade-insecure-requests
    • description
      We have recently released version 4.6.0 for CRS 4, fixing a serious problem. As this problem affects CRS 3 as well, we also did a backport release for v3. …
  • Open Graph Meta Tags

    5
    • og:title
      CRS versions 4.6.0 and 3.3.6 have been released
    • og:description
      We have recently released version 4.6.0 for CRS 4, fixing a serious problem. As this problem affects CRS 3 as well, we also did a backport release for v3. (3.3.6). All users are requested to update to the new releases. The new releases tackle two multipart file upload bypass methods that were reported by @luelueking: Wrapping the Content-Disposition with non-printable characters like \x0e (e.g. “%0e Content-Disposition %0e”) may allow the header to go undetected by the WAF engine as it may not be correctly parsed.
    • og:type
      article
    • og:url
      https://coreruleset.org/20240829/crs-versions-4.6.0-and-3.3.6-have-been-released/
    • og:image
      https://coreruleset.org/images/social-preview.svg
  • Twitter Meta Tags

    4
    • twitter:card
      summary_large_image
    • twitter:image
      https://coreruleset.org/images/social-preview.svg
    • twitter:title
      CRS versions 4.6.0 and 3.3.6 have been released
    • twitter:description
      We have recently released version 4.6.0 for CRS 4, fixing a serious problem. As this problem affects CRS 3 as well, we also did a backport release for v3. (3.3.6). All users are requested to update to the new releases. The new releases tackle two multipart file upload bypass methods that were reported by @luelueking: Wrapping the Content-Disposition with non-printable characters like \x0e (e.g. “%0e Content-Disposition %0e”) may allow the header to go undetected by the WAF engine as it may not be correctly parsed.
  • Link Tags

    9
    • apple-touch-icon
      https://coreruleset.org/apple-touch-icon.png
    • icon
      https://coreruleset.org/favicon.ico
    • icon
      https://coreruleset.org/favicon.svg
    • icon
      https://coreruleset.org/favicon-32x32.png
    • preload
      https://coreruleset.org/fonts/nunito-v25-latin-regular.woff2

Links

36