For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

saidshow's avatar
saidshow
Icon for Cirrus rankCirrus
Sep 13, 2019

Can the F5 Mitigate the HTTP/2 vulnerabilities?

Hi,

 

We are considering implementing HTTP/2 in our environment at the moment. In August a number of DoS vulnerabilities were identified in HTTP/2. If we make the change for HTTP/2 on the F5, does the F5 do anything to mitigate the risk?

 

https://nakedsecurity.sophos.com/2019/08/19/netflix-finds-multiple-http2-dos-flaws/

 

Are there ASM signatures that protect against these issues? If so, what about protection on APM if we add HTTP/2 there?

 

Any information would be appreciated.

No RepliesBe the first to reply