Possible dereference of Null
In result of static analyse of nginx source code (including ngx_http_modsecurity_module) with Svace static analyzer I found error of cathegory "DEREFERENCE OF NULL" (checker finds situations where possible value equal to null can be dereferenced) in ngx_http_modsecurity_module.c
Initialization with possible null returned value here: https://github.com/owasp-modsecurity/ModSecurity-nginx/blob/fd28e6ae3bc9e3e33e5ab177afce5c24af41a6ed/src/ngx_http_modsecurity_module.c#L202
And dereference of location->key field here:
https://github.com/owasp-modsecurity/ModSecurity-nginx/blob/fd28e6ae3bc9e3e33e5ab177afce5c24af41a6ed/src/ngx_http_modsecurity_module.c#L203
Found by Linux Verification Center with SVACE
I think that a check should be added to the value assigned to the location variable.
Hi @LM4O322,
could you send a PR to fix this issue?