diff --git a/nginx/modsecurity/global-exceptions.conf b/nginx/modsecurity/global-exceptions.conf index 4a81089..20f9584 100644 --- a/nginx/modsecurity/global-exceptions.conf +++ b/nginx/modsecurity/global-exceptions.conf @@ -13,6 +13,8 @@ SecRule REQUEST_URI "@streq /.well-known/caldav" "id:10002,phase:1,nolog,pass,ct SecRule REQUEST_URI "@streq /.well-known/carddav" "id:10003,phase:1,nolog,pass,ctl:ruleEngine=Off" SecRule REQUEST_URI "@beginsWith /ocs/v2.php/apps/user_status/api/v1/heartbeat" \ "id:1001,phase:2,pass,nolog,ctl:ruleRemoveById=942100,msg:'TUNING: Falso-positivo de SQLi (942100) removido para a API de heartbeat'" +SecRule REQUEST_URI "@beginsWith /ocs/v2.php/apps/user_status/api/v1/heartbeat" \ + "id:1001,phase:2,pass,nolog,ctl:ruleRemoveById=920350,msg:'TUNING: Falso-positivo (920350) removido para a API de heartbeat'" SecRule REQUEST_URI "@beginsWith /apps/files/api/v1/config/sort_favorites_first" \ "id:1002,phase:2,pass,nolog,ctl:ruleRemoveById=920420,msg:'TUNING: Falso-positivo de decodificacao (920420) removido para a API de config'" SecRule REQUEST_URI "@beginsWith /apps/files/api/v1/config/show_hidden" \