Forum Discussion
GVR_Dinesh_1748
Nov 07, 2018Nimbostratus
Configure iRule for CWE ID 352 CWE name Cross-Site Request Forgery (CSRF) vulnerability
How to configure the irule to fix the vulnerability CWE ID 352 CWE name Cross-Site Request Forgery (CSRF) in F5.
FA_Session cookie is set by f5 load balancer to route request to same app servers from which response was sent. Can you please set the following attribute on F5 cookie "SameSite=strict"
- Lee_SutcliffeNacreous
There a very good article that explains this problem and provides an iRule and a traffic policy example on how to mitigate this CVE
https://devcentral.f5.com/articles/increased-security-with-first-party-cookies-30715
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects