Bug 276817 - security/modsecurity3: Update to v3.0.12
Summary: security/modsecurity3: Update to v3.0.12
Status: Closed FIXED
Alias: None
Product: Ports & Packages
Classification: Unclassified
Component: Individual Port(s) (show other bugs)
Version: Latest
Hardware: Any Any
: --- Affects Only Me
Assignee: Kurt Jaeger
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-02-04 08:46 UTC by Wolfgang Gerlach
Modified: 2024-03-16 13:18 UTC (History)
4 users (show)

See Also:
pi: maintainer-feedback-


Attachments
Patch (1006 bytes, patch)
2024-02-04 08:46 UTC, Wolfgang Gerlach
no flags Details | Diff
Poudriere build (3.39 KB, text/plain)
2024-03-15 08:41 UTC, Wolfgang Gerlach
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Wolfgang Gerlach 2024-02-04 08:46:50 UTC
Created attachment 248170 [details]
Patch

The attached patch updates modsecurity3 to version 3.0.12.

- Fixes the security vulnerability CVE 2024-1019 (https://github.com/owasp-modsecurity/ModSecurity/releases/tag/v3.0.12)
Comment 1 Wolfgang Gerlach 2024-03-05 18:23:53 UTC
Unfortunately, the ticket has been lying around almost unprocessed for a month now. Is there a reason for this? Have I forgotten something, for example?
Comment 2 Daniel Engberg freebsd_committer freebsd_triage 2024-03-14 20:46:23 UTC
Hi,

While it's not a requirement it usually reduces time to process reports by quite a bit if you can do a build test(s) using Poudriere.

Also, including relevant information such as is it run-tested and if so list os ver, arch and relevant software and their version(s).

Best regards,
Daniel
Comment 3 Wolfgang Gerlach 2024-03-15 08:41:06 UTC
Hi Daniel,

Thank you for your answer. The build test with Poudriere was successful.
We are using the new version productively since 05.02.2024.

OS: 14.0-RELEASE-p5
Arch: amd64

Best regards,
Wolfgang
Comment 4 Wolfgang Gerlach 2024-03-15 08:41:49 UTC
Created attachment 249182 [details]
Poudriere build
Comment 5 Kurt Jaeger freebsd_committer freebsd_triage 2024-03-15 21:47:32 UTC
(In reply to Wolfgang Gerlach from comment #4)
Thanks for the patch. I'll work on it tomorrow.

It's enough to mention the poudriere builds you did, please do not
attach the build logs. Reason: It bloats the bugzilla database.
Comment 6 commit-hook freebsd_committer freebsd_triage 2024-03-16 13:18:25 UTC
A commit in branch main references this bug:

URL: https://cgit.FreeBSD.org/ports/commit/?id=e1d28513d03190ae18df0041926d23828e8ec760

commit e1d28513d03190ae18df0041926d23828e8ec760
Author:     Wolfgang Gerlach <wolfgang.gerlach@proton.me>
AuthorDate: 2024-03-16 13:16:09 +0000
Commit:     Kurt Jaeger <pi@FreeBSD.org>
CommitDate: 2024-03-16 13:16:09 +0000

    security/modsecurity3: update 3.0.8 -> 3.0.12

    - Trustwave transfered ModSecurity custodianship to OWASP
      effective January 25, 2024
    - Fixes CVE 2024-1019

    PR:             276817
    Changes:        https://github.com/owasp-modsecurity/ModSecurity/releases

 security/modsecurity3/Makefile | 4 ++--
 security/modsecurity3/distinfo | 6 +++---
 2 files changed, 5 insertions(+), 5 deletions(-)
Comment 7 Kurt Jaeger freebsd_committer freebsd_triage 2024-03-16 13:18:45 UTC
Committed, thanks!