Bug ID 759664: Remove Event Listener support of edge case

Last Modified: Mar 21, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP FPS(all modules)

Known Affected Versions:
13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 14.0.0, 14.0.0.1, 14.0.0.2, 14.0.0.3, 14.0.0.4, 14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3

Opened: Feb 26, 2019
Severity: 3-Major

Symptoms

In cases where the protected input field isn't located under the form tag, the Remove Event Listener removes the malicious event listeners of the input field, but the field itself is missing in the traffic (that is being sent on submit).

Impact

If an edge case situation, the entered values won't be sent when submitting the form.

Conditions

protected inputs located outside of the form tag. For example: ------------ <form> .. </form> <input name="username">

Workaround

None

Fix Information

None

Behavior Change