They’ve suggested blocking ${ in the request
location ~\* \$\{. {
deny all;
}
but this only helps if this vulnerability is triggered using the request uri otherwise it's useless RewriteEngine On
RewriteCond %{REQUEST_URI} ^.*\${.*$
RewriteRule ^/(.*) https://google.com [R=302,L]
seems to work ... http-request deny if { path -m sub ${ }
http-request deny if { query -m sub ${ }
http-request deny if { path -m sub $%7B }
http-request deny if { query -m sub $%7B }
http-request deny if { path -m sub %24%7B }
http-request deny if { query -m sub %24%7B }