AnsweredAssumed Answered

Specific keyword(s) not allowed in POST operations with published web app?

Question asked by Timothy Morty on Nov 6, 2018
Latest reply on Nov 6, 2018 by Dameon Welch-Abernathy

Hello all

 

I'm wondering if anyone has had any issues with certain open source apps, etc. when publishing as a web app in MAB. For example, I have an XWiki site that is working well most of the time, but when creating or editing a post containing the word "find" and then previewing it, an error page is shown:

 

Error:  Access denied. The format or content of your request has been detected as invalid or unsafe. (400) 

 

If I change it to finding/finder, etc. then I can save and preview. When I looked in the logs, there are some IPS 'prevent' log entries referring to command injection. However I can't create an exception from the log and whitelisting the destination server in the IPS or inspection policy hasn't helped.

 

I've also used the option to not inspect content, etc. for the destination in the CVPN config file.

 

Can anyone suggest where else I could look?

Outcomes