Forum Discussion
samstep
Nov 04, 2018Cirrocumulus
First of all you need to make use you use CSRF only on URLs which need it (have CSRF vulnerability e.g. transactions) and these URLs to the Protected URLs list in ASM CSRF screen.
Secondly:
Version 11.5.4 has a known CSRF bug (ID474256) causing False Positive, more information here
https://cdn.f5.com/product/bugtracker/ID474256.html
So if you are affected (CSRF protection is needed in frames) then you need to upgrade to v12.x