Skip to content

REQUEST_COOKIES_NAMES crashes(?) coraza #1450

@louis-lau

Description

@louis-lau

Description

Hi!

This rule, taken directly out of the example docs:

SecRule &REQUEST_COOKIES_NAMES:JSESSIONID "@eq 0" "id:45"

Seems to crash coraza. In coraza-caddy it causes a failure state without any logging. (corazawaf/coraza-caddy#246).

But trying it inside https://playground.coraza.io/, it also seems to crash. Returning an undefined error, then erroring for every analysis ran afterward.

Steps to reproduce

Head to https://playground.coraza.io/, paste rule, press Analyze.

Expected result

Probably shouldn't crash :)

Actual result

Crash :)

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions