Skip to content

Releases: coreruleset/coreruleset

v4.21.0

02 Dec 08:51
v4.21.0
2ac6c00

Choose a tag to compare

What's Changed

🆕 New features and detections 🎉

🧰 Other Changes

Full Changelog: v4.20.0...v4.21.0

v4.20.0

02 Nov 14:17
v4.20.0
125990b

Choose a tag to compare

What's Changed

🆕 New features and detections 🎉

🧰 Other Changes

Full Changelog: v4.19.0...v4.20.0

v4.19.0

02 Oct 10:09
v4.19.0
5a9e41c

Choose a tag to compare

What's Changed

⭐ Important changes

🆕 New features and detections 🎉

🧰 Other Changes

New Contributors

Full Changelog: v4.18.0...v4.19.0

v4.18.0

03 Sep 21:55
v4.18.0
ad2b560

Choose a tag to compare

What's Changed

🆕 New features and detections 🎉

🧰 Other Changes

Full Changelog: v4.17.1...v4.18.0

v4.17.1

05 Aug 12:16
v4.17.1
1e82784

Choose a tag to compare

What's Changed

⭐ Important changes

  • chore: removed detection for LaTeX injection by @Xhoenix in #4221

🧰 Other Changes

Full Changelog: v4.17.0...v4.17.1

v4.17.0

31 Jul 18:58
v4.17.0
dc9886a

Choose a tag to compare

Important

This release contains a new rule to detect LaTeX injections which was not supposed to be released as it is too prone to false positives in it's current state. Please use v4.17.1 instead.

What's Changed

⭐ Important changes

🆕 New features and detections 🎉

  • feat: added detection for ASP.NET errors by @Xhoenix in #4092
  • feat: added detection for RCE via Referer header by @Xhoenix in #3993
  • feat: added detection for LaTeX injection by @Xhoenix in #4206
  • feat: added detection for ruby errors and code leakage by @Xhoenix in #4089

🧰 Other Changes

New Contributors

Full Changelog: v4.16.0...v4.17.0

v4.16.0

29 Jun 14:50
v4.16.0
b6b3ffe

Choose a tag to compare

What's Changed

🆕 New features and detections 🎉

🧰 Other Changes

  • fix(941160): remove dot star by @fzipi in #4155
  • fix(934140): remove dot star by @fzipi in #4165
  • fix(932370): remove dot star by @fzipi in #4166
  • fix(955xxx): remove dot star by @Xhoenix in #4169
  • fix(933150): moving printf to 933160 for additional php syntax check (933150 PL-1, 933160 PL-1) by @EsadCetiner in #3840
  • fix: create a stricter sibling to 932370 and move at to PL-2 (932370 PL-1, 932371 PL-2) by @EsadCetiner in #4015
  • fix(942340): remove dot star by @fzipi in #4164
  • refactor(942340): move to regex assembly by @fzipi in #4014
  • fix(933160): remove dot star by @fzipi in #4167

New Contributors

Full Changelog: v4.15.0...v4.16.0

v4.15.0

03 Jun 10:22
v4.15.0
73eace1

Choose a tag to compare

What's Changed

🆕 New features and detections 🎉

🧰 Other Changes

Full Changelog: v4.14.0...v4.15.0

v4.14.0

29 Apr 12:55
v4.14.0
b5b788b

Choose a tag to compare

What's Changed

🆕 New features and detections 🎉

🧰 Other Changes

Full Changelog: v4.13.0...v4.14.0

v4.13.0

31 Mar 15:21
v4.13.0
4e08c28

Choose a tag to compare

What's Changed

⭐ Important changes

  • fix(security): fixing double URL decode of REQUEST_URI by @azurit in #4047

🆕 New features and detections 🎉

🪦 Rule removals

  • feat: remove rule 952100 for detecting Java Source Code Leakage by @S0obi in #4052

🧰 Other Changes

  • fix(934130): extend prototype pollution payload by @Xhoenix in #4036
  • fix: rule 930110 is not supposed to match bare '..' without (back)slashes by @azurit in #4050
  • fix: use boundary to fix false positive with email [email protected] by @EsadCetiner in #4045
  • feat: refresh restricted-upload.data by @S0obi in #4046
  • fix: tag inconsistency per file by @Xhoenix in #4031
  • fix: added pre-check of unset TX variable by @airween in #4066
  • fix: false positive found in quantitative testing round 2 for unix rce rules (932230 PL-1, 932235 PL-1, 932250 PL-1, 932260 PL-1, 932231 PL-2, 932220 PL-2, 932236 PL-2, 932239 PL-2, 932232 PL-3, 932238 PL-3) by @EsadCetiner in #4019

New Contributors

Full Changelog: v4.12.0...v4.13.0