Forum Discussion
Brian_Achenbaugh
Sep 29, 2022Cirrus
Cookies, jsessionid and encryption
Hi All, Im relatively new to this. Our company had a third party do a pentest on our External apps in a DMZ. We had one call out for cookie information disclosure, so we turned on cookie encryption...
PSilva
Ret. Employee
Maybe add the solution if others are experiencing the same?
Brian_Achenbaugh
Sep 30, 2022Cirrus
So based on the info in this article:
The person wanted to actually insert load balancing info into the universal persistence cookie as it wasnt there, so that sort of cleared my concern that it would be exposed like in a normal load balancing cookie. Im hoping my assumption was correct.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects