Bug ID 674909: Application CSS injection might not work as expected when connection is congested

Last Modified: Oct 07, 2023

Affected Product(s):
BIG-IP FPS(all modules)

Known Affected Versions:
12.1.0, 12.1.1, 12.1.2, 13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3

Fixed In:
14.0.0, 13.1.0, 13.0.1, 12.1.3

Opened: Jul 20, 2017

Severity: 3-Major

Symptoms

Large CSS files configured for phishing protection injection in FPS may be truncated upon response to client.

Impact

Pages may display incorrectly in client browser depending on application requirements with specific CSS. Application functionality might not work as expected.

Conditions

-- Inject into Application CSS enabled in Anti-Fraud Profile :: Advanced :: Phishing Detection. -- Large CSS file such as bootstrap files configured for Application CSS Locations. -- Network congestion engaging TMM flow control.

Workaround

You can use either of the following workarounds: -- Remove affected large files from Application CSS Locations. -- Disable Inject into Application CSS entirely.

Fix Information

FPS now handles the case where injecting to application CSS is interrupted by congestion.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips