Bug ID 589606: CSRF enabled within iframe request causes to unpredictable behavior on a website.

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP ASM(all modules)

Known Affected Versions:
12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2

Fixed In:
13.0.0

Opened: Apr 26, 2016

Severity: 3-Major

Symptoms

The csrf script changes the frame/iframe source attribute. When it happens the browser issue a request, as a result for each frame on a page 2 requests are being sent, the first is the original request when the frame is loaded and the second is when the csrf script changes the frame source attribute.

Impact

Viewing the site causes some pages to show up blank.

Conditions

Enable ASM CSRF Request a page with an iframe or frameset

Workaround

Bypassing or disabling ASM for URL appears to fix the issue.

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips