CSRF Protection

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

CSRF Protection

L3 Networker

GlobalProtect portal page isn't protected by anti-CSRF tokens. Is it possible to add this protection?

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

the portal is never used in a browser unless to download the agent one time. you could disable the portal externally if you find your users continually logging on for no reason?

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

the portal is never used in a browser unless to download the agent one time. you could disable the portal externally if you find your users continually logging on for no reason?

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

@reaper  Hmm, What about clientless VPN?

L0 Member

Hi dear, how you're today?
I wanna to ask you about the vulnerability known as CSRF (Cross-Site Request Forgery) in the portal of Global Protect in a web browser in a NGFW I have this problem,
Do you know of a possible solution to this problem or a guide to avoid this problem?

Thanks you for your help,

Sincerely.

  • 1 accepted solution
  • 4073 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!