From 9c462dda2eeeaf24de7477f62f5b543c220b6be4 Mon Sep 17 00:00:00 2001 From: ale <ale@incal.net> Date: Wed, 26 Aug 2020 12:03:47 +0100 Subject: [PATCH] Disable modsec rule 930110 --- .../crs/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/conf/modsecurity/crs/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf b/conf/modsecurity/crs/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf index ef94eed..6903e9e 100644 --- a/conf/modsecurity/crs/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf +++ b/conf/modsecurity/crs/RESPONSE-999-EXCLUSION-RULES-AFTER-CRS.conf @@ -29,3 +29,7 @@ SecRuleRemoveByID 953120 # Filters dangerous file extensions in the URL. SecRuleRemoveByID 920440 + +# Having '../' in the response body. +SecRuleRemoveByID 930110 + -- GitLab