Skip to content

fix(931130): ensure correct target is logged#4577

Merged
EsadCetiner merged 3 commits into
coreruleset:mainfrom
EsadCetiner:fix-931130-logging-parameter
Mar 28, 2026
Merged

fix(931130): ensure correct target is logged#4577
EsadCetiner merged 3 commits into
coreruleset:mainfrom
EsadCetiner:fix-931130-logging-parameter

Conversation

@EsadCetiner
Copy link
Copy Markdown
Member

Proposed changes

931130 does not log the correct matched variable name and instead just logs the matched TX collection. This behavior can be confusing when trying to write a rule-exclusion to exclude a specific target. This PR creates another TX variable which contains the correct variable name.

PR Checklist

  • I have read the CONTRIBUTING doc
  • I have added positive tests proving my fix/feature works as intended.
  • I have added negative tests that prove my fix/feature considers common cases that might end in false positives
  • In case you changed a regular expression, you are not adding a ReDOS for pcre. You can check this using regexploit
  • My test use the comment field to write the expected behavior
  • I have added documentation for the rule or change (when appropriate)

Further comments

For the reviewer

  • Positive and negative tests were added
  • Tests cover the intended fix/feature properly
  • No usage of dangerous constructs like ctl:requestBodyAccess=Off were used in the rule
  • In case a regular expression was changed, there is no ReDOS
  • Documentation is clear for the rule/change

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Mar 28, 2026

📊 Quantitative test results for language: eng, year: 2023, size: 10K, paranoia level: 1:
🚀 Quantitative testing did not detect new false positives

@EsadCetiner EsadCetiner requested a review from a team March 28, 2026 04:20
@EsadCetiner EsadCetiner added this pull request to the merge queue Mar 28, 2026
Merged via the queue into coreruleset:main with commit 886c929 Mar 28, 2026
8 checks passed
@EsadCetiner EsadCetiner deleted the fix-931130-logging-parameter branch March 28, 2026 07:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants