Last Modified: Apr 28, 2025
Affected Product(s):
BIG-IP ASM
Fixed In:
17.5.0
Opened: Sep 29, 2023 Severity: 3-Major
A request with JWT that holds a 'kid' in its header, which seems to be identical to one of the JWKs that is attached to the access profile may cause a malformed violation: "JWT 'kid' is not matching any valid JWK 'kid'"
A request with a valid JWT may be blocked
Import JWKs file with unsupported x5c format
Import valid JWKs file
A valid JWT request will not cause a malformed violation