F5-K000138650: Low severity f5 big-ip next (ltm) vulnerability
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with domain=co.UK when the URL used a lower case hostname curl.co.uk, even though co.uk is listed as a PSL domain.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000138650?
F5-K000138650 is considered a medium severity vulnerability due to its potential to allow super cookies to be set by malicious servers.
How do I fix F5-K000138650?
To fix F5-K000138650, users should upgrade to the latest version of the affected products, specifically version 20.1.0 or above.
What are the affected software versions for F5-K000138650?
Affected software versions for F5-K000138650 include certain versions of F5 BIG-IP, BIG-IP Next, BIG-IP Next Central Manager, and others based on the specified version ranges.
What could happen if F5-K000138650 is exploited?
If F5-K000138650 is exploited, it could enable a malicious HTTP server to set cookies that are incorrectly shared across multiple unrelated sites, compromising user data.
Is there a workaround for F5-K000138650?
Currently, the recommended mitigation for F5-K000138650 is to apply the necessary software updates to prevent exploitation.