Last Modified: Apr 04, 2025
Affected Product(s):
BIG-IP ASM
Fixed In:
17.5.0
Opened: Apr 09, 2024 Severity: 3-Major
A specific csrftoken value bypasses the signature check
Request is not blocked leading to a false negative
- ASM policy with "All Signatures" set exists - Request is sent with a specific csrftoken value
None
Request is blocked as expected