Hi F5 community,
I'm using these F5 rules for AWS WAF with API Gateway and Application Load Balancer resources.
How do I know these vulnerabilities are no impact on AWS WAF? or
Has it been fixed in the F5 rules? or
Do I need to create a custom F5 rules to protect these vulnerabilites?
I'm not sure I understand it correctly but it seems for F5 appliance or others which is not SaaS, on AWS.
So, I would like to know the vulnerabilties are no impact on the F5 AWS WAF rules and F5 has updated signatures to protect this issue.
Could you please provide more details for AWS WAF specific areas?
All the Support info is here: https://community.f5.com/t5/technical-forum/k24912123-mitigate-the-spring-framework-spring4shell-and...
And, there was a Signiture Update Yesterday - Select Product and Path at https://downloads.f5.com/esd/productlines.jsp