F5-K000138650: Low severity f5 big-ip next (ltm) vulnerability

Published Feb 21, 2024
·
Updated

This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with domain=co.UK when the URL used a lower case hostname curl.co.uk, even though co.uk is listed as a PSL domain.

Affected Software

8 affected componentsFixes available
F5 BIG-IP Next>=20.0.1<=20.0.2
20.1.0
F5 BIG-IP Next Central Manager>=20.0.1<=20.0.2
20.1.0
F5 BIG-IP Next SPK>=1.7.0<=1.9.1
F5 BIG-IP Next CNF>=1.1.0<=1.2.1
F5 BIG-IP>=17.1.0<=17.1.1
F5 BIG-IP>=16.1.0<=16.1.4
F5 BIG-IP>=15.1.0<=15.1.10
F5 BIG-IQ Centralized Management>=8.0.0<=8.3.0

Event History

Feb 21, 2024
Advisory Published
via F5·07:57 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of F5-K000138650?

F5-K000138650 is considered a medium severity vulnerability due to its potential to allow super cookies to be set by malicious servers.

2

How do I fix F5-K000138650?

To fix F5-K000138650, users should upgrade to the latest version of the affected products, specifically version 20.1.0 or above.

3

What are the affected software versions for F5-K000138650?

Affected software versions for F5-K000138650 include certain versions of F5 BIG-IP, BIG-IP Next, BIG-IP Next Central Manager, and others based on the specified version ranges.

4

What could happen if F5-K000138650 is exploited?

If F5-K000138650 is exploited, it could enable a malicious HTTP server to set cookies that are incorrectly shared across multiple unrelated sites, compromising user data.

5

Is there a workaround for F5-K000138650?

Currently, the recommended mitigation for F5-K000138650 is to apply the necessary software updates to prevent exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203