Bug ID 1028473: URL sent with trailing slash might not be matched in ASM policy

Last Modified: Nov 07, 2022

Bug Tracker

Affected Product:  See more info
BIG-IP ASM(all modules)

Known Affected Versions:
14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.5, 14.1.0.6, 14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 14.1.2.7, 14.1.2.8, 14.1.3, 14.1.3.1, 14.1.4, 14.1.4.1, 14.1.4.2, 14.1.4.3, 14.1.4.4, 14.1.4.5, 14.1.4.6, 15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1, 15.1.2, 15.1.2.1, 15.1.3, 15.1.3.1, 15.1.4, 15.1.4.1, 15.1.5, 15.1.5.1, 15.1.6, 16.1.0, 16.1.1, 16.1.2, 16.1.2.1

Fixed In:
17.0.0, 16.1.2.2, 15.1.6.1, 14.1.5

Opened: Jun 24, 2021
Severity: 3-Major

Symptoms

Request sent to a specific URL with added trailing slash may not be handled according to expected policy.

Impact

URL enforcement is not done according to expected rules.

Conditions

-- Request is sent with URL containing trailing slash. -- Security policy contains the same URL, but without slash.

Workaround

Add configuration for same URL with added trailing slash.

Fix Information

URL with trailing slash is now handled as expected.

Behavior Change