-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
🐛 urls with .profile
in them are triggering a modsec rule resulting in a 403 page forbidden error
#982
Comments
Failing Examples
|
|
Current PR resolves the issue, still researching if more refinements can be made.PR |
Describe the bug.
It appears urls for details of tables in find moj data that start
profile
are triggering a modsec ingress rule that blocks the page being displayed with a 403 error.This is across all environments
The modsec logs indicate the rule id doing the block is 949110 (Inbound Anomaly Score Exceeded)
However, this is going to be more complicated to properly understand and mitigate because the rule is an aggregation of scores from other rules and we can't disable or override the 949110 rule, we'll need to dig into it and find the rule(s) which is(are) triggered
To Reproduce
No response
Expected Behaviour
No response
Additional context
No response
The text was updated successfully, but these errors were encountered: