Bug ID 759664: Remove Event Listener support of edge case

Last Modified: Sep 11, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP FPS(all modules)

Known Affected Versions:
13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4, 13.1.1.5, 13.1.3, 14.0.0, 14.0.0.1, 14.0.0.2, 14.0.0.3, 14.0.0.4, 14.0.0.5, 14.0.1, 14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.4, 14.1.0.5, 14.1.0.6, 14.1.2, 15.0.0, 15.0.1

Opened: Feb 26, 2019
Severity: 3-Major

Symptoms

In cases where the protected input field is not located under the form tag, the Remove Event Listener removes the malicious event listeners of the input field, but the field itself is missing in the traffic (that is being sent on submit).

Impact

In an edge-case situation, the entered values are not sent when submitting the form.

Conditions

Protected inputs located outside of the form tag. For example: <form> ... </form> <input name="username">

Workaround

None.

Fix Information

None

Behavior Change