Forum Discussion
CVE mitigation on F5 XC vs classic F5 WAF
Yes that is how XC with AWAF works. Any new signatures are auto added. Changed and new signatures enter 1 week staging as shown in WAF Signature Staging in F5 Distributed Cloud and you need to use the XC API to see them (no GUI option for some reason) https://docs.cloud.f5.com/docs-v2/api/waf-signatures-changelog
Maybe for this one as it is bad XC added it to blocking even for WAF policies that have staging enabled from the start but I suggest using the XC API to check.
When you said XC doesn't have the signature where did you actually check this as I know only of https://docs.cloud.f5.com/docs-v2/platform/reference/attack-signatures ?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com