Skip to content

docker部署V7.0.2版本,当出现“常规sql注入检测“拦截日志时整个waf崩溃 #148

@zyufstudio

Description

@zyufstudio

测试多次程序了,当出现“常规sql注入检测“拦截日志时整个waf都会崩溃,导致所以站点都无法访问
Image

请求报文:
path="/mydrive"
POST //webapi/entry.cgi HTTP/1.1
X-Waf-Ip:
Content-Length: 144
Host:
Content-Type: application/x-www-form-urlencoded
X-Waf-Id: 1;
User-Agent: Synology-Synology_Drive_3.8.0_rv:1061_PJE110_Android_34_(Dalvik/2.1.0 (Linux; U; Android 14; PJE110 Build/TP1A.220905.001))
Connection: Keep-Alive
Accept-Encoding: gzip

api=SYNO.SynologyDrive.Files&version=5&method=get&path=%22%2Fmydrive%22&case_sensitive=false&access_token=%226fc343dac5355f7a2a4543f93666a2fdf49fafd8%22

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions