Andy101
Jul 23, 2021Nimbostratus
False Positive on AWS WAF F5 Managed Rule F5#OWASP_Managed#rule_div_tag__behavior__Parameter__AllQueryArguments_Body
Hello
I'm not sure if this is a question for AWS support or F5 but I'll start with F5support.
We recently enabled 2 sets of rules on a AWS WAFv2 from F5 (F5-CVE_Managed and F5-OWASP_Managed).
Once we did we started seeing a false positive for an API call with the following rule...
F5#OWASP_Managed#rule_div_tag__behavior__Parameter__AllQueryArguments_Body
After some further investigation we discovered the rule is tripped when we make a request which contains embeded HTML in the body and this HTML contains a div tag with a base64 encoded image.
Can you give us more background information on exactly what this rule is doing and how we should go about avoiding this false positive?
Andy