Last Modified: May 29, 2024
Affected Product(s):
BIG-IP LTM
Known Affected Versions:
13.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 13.1.3.1
Fixed In:
15.1.0, 14.1.2.8, 13.1.3.2
Opened: May 13, 2019 Severity: 3-Major
The BIG-IP system does not preserve WebSocket frames. Frame headers and payload may be reordered such that a header for a second frame may be sent out in the middle of a first frame's payload. Frame boundaries get skewed and payload gets interpreted as headers.
WebSocket frames are not preserved such that traffic appears to be garbage. -- If request logging is enabled, client frames may not be preserved. -- If response logging is enabled, server frames may not be preserved.
A request logging profile is configured on a WebSocket virtual server.
Remove the request logging profile.
None