Last Modified: Nov 02, 2023
BIG-IP (all modules)
Known Affected Versions:
16.1.3, 184.108.40.206, 220.127.116.11, 18.104.22.168, 22.214.171.124, 126.96.36.199
Opened: Dec 05, 2022 Severity: 3-Major
In some cases of WEBSSO same token is sent to different sessions in the backend.
Situations where JWTs (via WEBSSO / OAuth Bearer profile) are being sent downstream for requests which belong to a different user. The problem seems to be related to when these requests share the same client IP address. This is a big problem when clients are using NAT themselves to mask different users/sessions behind the same IP address.
WEBSSO with an OAuth Bearer token and the Cache option enabled cached tokens from a diff per-session context are flowed to the backend application
When sessions are different we are clearing the cache tokens so that new tokens are generated for different sessions.