Bug ID 593681: CSRF doesn't look correctly into relative urls in the location header

Last Modified: Sep 13, 2023

Affected Product(s):
BIG-IP ASM(all modules)

Known Affected Versions:
11.5.4, 11.5.5, 11.5.6, 11.5.7, 11.5.8, 11.5.9, 11.5.10, 11.6.0, 11.6.1, 11.6.2, 11.6.3, 11.6.3.1, 11.6.3.2, 11.6.3.3, 11.6.3.4, 11.6.4, 11.6.5, 11.6.5.1, 11.6.5.2, 11.6.5.3, 12.0.0, 12.0.0 HF1, 12.1.0 HF1, 12.0.0 HF2, 12.1.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.1 HF1, 12.1.1 HF2, 12.1.2 HF1, 12.1.2 HF2, 12.1.0, 12.1.1, 12.1.2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 12.1.4.1, 12.1.5, 12.1.5.1, 12.1.5.2, 12.1.5.3, 12.1.6

Fixed In:
13.0.0

Opened: May 17, 2016

Severity: 3-Major

Related Article: K33014810

Symptoms

CSRF does not correctly look into relative URLs in the location header.

Impact

in some cases the location header is searched in the configuration as is, and is not found since it doesn't match the wildcard, which can trigger false positive CSRF violations.

Conditions

There is a relative URL in the location header.

Workaround

None.

Fix Information

CSRF now correctly looks into relative URLs in the location header.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips