diff --git a/docker/conf/modsecurity/crs/crs-setup.conf b/docker/conf/modsecurity/crs/crs-setup.conf index bd7adb51d4dc958d9a2cf8023879cf0a7f487468..80d0a24fdc15d788c228d3be0686601db2825714 100644 --- a/docker/conf/modsecurity/crs/crs-setup.conf +++ b/docker/conf/modsecurity/crs/crs-setup.conf @@ -428,13 +428,13 @@ SecAction \ # Blocking Proxy header prevents 'httpoxy' vulnerability: https://httpoxy.org # Default: /proxy/ /lock-token/ /content-range/ /if/ # Uncomment this rule to change the default. -#SecAction \ -# "id:900250,\ -# phase:1,\ -# nolog,\ -# pass,\ -# t:none,\ -# setvar:'tx.restricted_headers=/proxy/ /lock-token/ /content-range/ /if/'" +SecAction \ + "id:900250,\ + phase:1,\ + nolog,\ + pass,\ + t:none,\ + setvar:'tx.restricted_headers=/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/'" # File extensions considered static files. # Extensions include the dot, lowercase, enclosed by /slashes/ as delimiters.