Impact
Libmodsecurity3 can't decode encoded HTML entities if they contains leading zeroes. This bug exists only in libmodsecurity3 v3.0.13. This allows the payload to be bypassed without inspection.
Patches
The library has the fix, v3.0.14 contains that.
Workarounds
No known workaround.
References
See issue #3340
Impact
Libmodsecurity3 can't decode encoded HTML entities if they contains leading zeroes. This bug exists only in libmodsecurity3 v3.0.13. This allows the payload to be bypassed without inspection.
Patches
The library has the fix, v3.0.14 contains that.
Workarounds
No known workaround.
References
See issue #3340