Open
Description
Preconditions and environment
- 2.4.6
- 5c8ef9d
- A file ending or starting with a tilde, is very often a temp file. Some WaFs, tend to block these requests as it could mean an attempt to abuse old temp files for fetching information.
Steps to reproduce
Check URLs in checkout for example
Expected result
Another character that does not suggest an attempt to abuse temp files should be used.
Actual result
A tilde is used and often ends up at the start or the end of the path
Additional information
No response
Release note
No response
Triage and priority
- Severity: S0 - Affects critical data or functionality and leaves users without workaround.
- Severity: S1 - Affects critical data or functionality and forces users to employ a workaround.
- Severity: S2 - Affects non-critical data or functionality and forces users to employ a workaround.
- Severity: S3 - Affects non-critical data or functionality and does not force users to employ a workaround.
- Severity: S4 - Affects aesthetics, professional look and feel, “quality” or “usability”.
Metadata
Metadata
Assignees
Labels
Gate 3 Passed. Manual verification of the issue completed. Issue is confirmedMay be fixed according to the position in the backlog.Indicates original Magento version for the Issue report.The issue has been reproduced on latest 2.4-develop branchIssue related to Developer Experience and needs help with Triage to Confirm or Reject it