From 7fc98247acb987d59fe8d1e3ad11a8b06cacdc09 Mon Sep 17 00:00:00 2001 From: Esad Cetiner <104706115+EsadCetiner@users.noreply.github.com> Date: Fri, 29 Nov 2024 07:31:49 +1100 Subject: [PATCH] fix: sync allowed content types to fix 9EA-241022 (#13) --- plugins/sogo-rule-exclusions-before.conf | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugins/sogo-rule-exclusions-before.conf b/plugins/sogo-rule-exclusions-before.conf index c8ec7be..92992c7 100644 --- a/plugins/sogo-rule-exclusions-before.conf +++ b/plugins/sogo-rule-exclusions-before.conf @@ -39,7 +39,7 @@ SecRule &TX:allowed_request_content_type "@eq 0" \ pass,\ nolog,\ ver:'sogo-rule-exclusions-plugin/1.0.2',\ - setvar:'tx.allowed_request_content_type=|application/x-www-form-urlencoded| |multipart/form-data| |multipart/related| |text/xml| |application/xml| |application/soap+xml| |application/json| |application/cloudevents+json| |application/cloudevents-batch+json|'" + setvar:'tx.allowed_request_content_type=|application/x-www-form-urlencoded| |multipart/form-data| |text/xml| |application/xml| |application/soap+xml| |application/json|'" # Fix SOGo cookie false positive SecRule REQUEST_FILENAME "@beginsWith /SOGo/" \