laptop and a wrench

漏洞

In ArcGIS Pro 2.6.3, a query is prompted in Portal for ArcGIS on the group information via a POST request (token appended) with no content in the body. This triggers the F5 Silverline Web Application Firewall (WAF) (possibly others) to block the traffic as it detects a potential HTTP request smuggling operation. It also occurs when performing search operations against the Portal for ArcGIS. ArcGIS Pro should perform a GET request to retrieve these items.

ArcGIS Pro
漏洞 ID 编号 BUG-000135580
已提交November 19, 2020
上次修改时间December 12, 2024
适用范围ArcGIS Pro
找到的版本2.6.3
操作系统Windows OS
操作系统版本10.0 64 Bit
状态Non-Reproducible

附加信息

Please upgrade to the latest version of ArcGIS Pro.

解决办法

Explicitly allow the blocked traffic in the Web Application Firewall (WAF).

重现步骤

漏洞 ID: BUG-000135580

软件:

  • ArcGIS Pro

当漏洞状态发生变化时获得通知

下载 Esri 支持应用程序

发现关于本主题的更多内容

获取来自 ArcGIS 专家的帮助

联系技术支持部门

下载 Esri 支持应用程序

转至下载选项