-
Notifications
You must be signed in to change notification settings - Fork 231
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ModSecurity CRS Firewall Rules #17775
Comments
I can confirm this issue: after enabling mod_security on a server running both apache2 websites and Synapse homeserver, the homeserver stopped working. Logs are flooded with messages like:
|
work-around suggested here, have not tested it: coreruleset/coreruleset#1321 |
Seems fine if the community wanted to add the necessary rules for Synapse but I don't think we're interested in maintaining a 3rd party ruleset. |
Description:
Many popular web applications like Wordpress have open firewall rules to prevent false positives for those who run application firewalls by helping the firewall better understand the applications under it. Synapse and other servers should add firewall rules to the CoreRuleSet Plugin Registry.
The text was updated successfully, but these errors were encountered: