Эх сурвалжийг харах

Merge pull request #502 from mdr-engineering/feature/ftd_MSOCI-2279_FixWAFFalsePositives

Updates Cust SH WAF to allow latest false positives
Frederick Damstra 3 жил өмнө
parent
commit
a755e5ebcd

+ 4 - 0
base/splunk_servers/customer_searchhead/waf.tf

@@ -16,6 +16,7 @@ module "waf" {
     "SizeRestrictions_BODY",
     "SizeRestrictions_QUERYSTRING",
     "RestrictedExtensions_URIPATH",
+    "RestrictedExtensions_QUERYARGUMENTS",
     "EC2MetaDataSSRF_BODY",
     "GenericLFI_BODY",
   ]
@@ -27,6 +28,9 @@ module "waf" {
     "UNIXShellCommandsVariables_BODY",
     "UNIXShellCommandsVariables_QUERYARGUMENTS",
   ]
+  excluded_rules_AWSManagedRulesLinuxRuleSet = [
+    "LFI_QUERYSTRING",
+  ]
 
   # These are passed through and should be the same for module
   tags           = merge(local.standard_tags, var.tags)