Forum Discussion
L-CISIRH-BT-NET
Nimbostratus
Nov 02, 2018CSRF protection blocks the whole website instead of csrf attacks only
Hi everybody
Working on a VE 11.5.4 I need to activate the CSRF protection that my application does not provide.
The pb is that once activated, ASM blocks everything instead of a real attack. So...
samstep
Cirrocumulus
Nov 04, 2018First of all you need to make use you use CSRF only on URLs which need it (have CSRF vulnerability e.g. transactions) and these URLs to the Protected URLs list in ASM CSRF screen.
Secondly:
Version 11.5.4 has a known CSRF bug (ID474256) causing False Positive, more information here
https://cdn.f5.com/product/bugtracker/ID474256.html
So if you are affected (CSRF protection is needed in frames) then you need to upgrade to v12.x
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects