← Back to feed
Vulnerabilities & PatchesEmerging1 sourceNov 30, 2022 · 09:02via API Security News

Issue 210: CSRF vulnerability in F5, supply chain attacks, hacking APIs, GCP API security report

Brief

This week, we have news of another CSRF vulnerability affecting an API, this time in the F5 BIG-IP device. We also have an article from Dark Reading on the next generation of supply chain attacks, a quick guide on how to hack APIs, and finally, a very illuminating report from Google Cloud on API security research findings in 2022.

Vulnerability: CSRF vulnerability in F5 BIG-IP

Last week we featured a CSRF vulnerability in the Plesk server administration user interface, and this week we have a CSRF API vulnerability affecting the F5 BIG-IP device. Security researchers at Rapid7 discovered that the endpoint /iControl/iControlPortal. cgi lacks cross-site request forgery (CSRF) protection, nor does it require a correct Content-Type or other typical API protections.

Read more on API Security News