For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

khos77's avatar
khos77
Icon for Nimbostratus rankNimbostratus
Jul 20, 2022

F5 rules for AWS WAF

I have enabled the OWASP top 10 ruleset on one of our AWS WAFs however we are still seeing a High vulnerability for Reflected Cross-Site Scripting (XSS) in HTTP Header. Specifically in the cookie's cc_mode parameter.

I am looking for a way to protect against this type of attack.

1 Reply

  • Can you add the cc_parameter to the ruleset and then apply attack signatures to that parameter?