Operational Defect Database

BugZero found this defect 207 days ago.

F5 | 1382141

Query string gets stripped when bot defense redirects request via Location header, with versions that have the fix for ID890169

Last update date:

5/4/2024

Affected products:

BIG-IP

BIG-IP ASM

BIG-IP Install/Upgrade

Affected releases:

15.1.10

15.1.10.2

15.1.10.3

15.1.10.4

16.0.0

16.0.0.1

16.0.1

16.0.1.1

16.0.1.2

16.1.0

16.1.1

16.1.2

Fixed releases:

No fixed releases provided.

Description:

Bug ID 1382141: Query string gets stripped when bot defense redirects request via Location header, with versions that have the fix for ID890169 ... Last Modified: May 04, 2024 ... Severity: 3-Major ... Symptoms ... The query parameter is missing in the Location header, after upgrading to BIG-IP to the versions that have the fix for ID890169, with a redirect challenge. ... This can cause 307 redirect requests from the BIG-IP system. ... Impact ... Dropping query string results in an unrecognized resource request to the server. ... Conditions ... The bot profile is attached to the virtual server. ... Workaround

Additional Resources / Links

Share:

BugZero® Risk Score

What's this?

Coming soon

Status

Verified

Learn More

Search:

...