WAF and AppSec Controls
42 incident problems about WAF and AppSec Controls. Start with the reviewed ones.
Read first
How to split IAM, TLS, and WAF failures into a security operations flowAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when authentication, authorization, certificate, WAF, and audit log signals mix together and look like a single access failure.Security3 min readHow to isolate an mTLS trust bundle mismatchAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when the client certificate, server certificate, CA bundle, and sidecar reload timing differ and the handshake fails.Security3 min readHow to safely diagnose a WAF 403 false positiveAn InfraTree guide that lays out the first signals to check, the CLI verification order, common misdiagnoses, and a safe recovery path when it looks like a permissions problem but a specific header, payload, or rule group is blocking legitimate requests.Security3 min read
Recommended problems
Reviewed problems first, then problems with detailed scenarios.
SECURITY-033Managed WAF rule blocks a legitimate JSON admin requestThe API works for most clients, but a large or nested admin payload trips a managed protection rule and looks like an application bug at first glance.ReviewedSecurityIntermediate20 minFreeCORS blocks the new admin frontend's API calls with credentialsCORS blocks the new admin frontend's API calls with credentials is a hands-on troubleshooting drill. Read the browser's CORS error precisely and return the right headers for credentialed requests. WAF and AppSec Controls needs to be checked by narrowing scope, recent change, a...ReviewedSecurityBeginner14 minFreeCORS error: No 'Access-Control-Allow-Origin' header is presentCORS error: No 'Access-Control-Allow-Origin' header is present is a hands-on troubleshooting drill. Read the most common CORS error and decide which side has to change. WAF and AppSec Controls needs to be checked by narrowing scope, recent change, and the current live signal b...ReviewedSecurityBeginner3 minFreeMixed Content: a chat widget disappears after switching to HTTPSMixed Content: a chat widget disappears (WAF and AppSec Controls) is a hands-on troubleshooting drill. Recognise mixed-content blocking. WAF and AppSec Controls needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무에서는 operationa...ReviewedSecurityBeginner3 minFree
All problems (42)
CORS error: No 'Access-Control-Allow-Origin' header is presentCORS error: No 'Access-Control-Allow-Origin' header is present is a hands-on troubleshooting drill. Read the most common CORS error and decide which side has to change. WAF and AppSec Controls needs to be checked by narrowing scope, recent change, and the current live signal b...ReviewedSecurityBeginner3 minFreeMixed Content: a chat widget disappears after switching to HTTPSMixed Content: a chat widget disappears (WAF and AppSec Controls) is a hands-on troubleshooting drill. Recognise mixed-content blocking. WAF and AppSec Controls needs to be checked by narrowing scope, recent change, and the current live signal before rollback. 실무에서는 operationa...ReviewedSecurityBeginner3 minFreeSECURITY-033Managed WAF rule blocks a legitimate JSON admin requestThe API works for most clients, but a large or nested admin payload trips a managed protection rule and looks like an application bug at first glance.ReviewedSecurityIntermediate20 minFreeCORS blocks the new admin frontend's API calls with credentialsCORS blocks the new admin frontend's API calls with credentials is a hands-on troubleshooting drill. Read the browser's CORS error precisely and return the right headers for credentialed requests. WAF and AppSec Controls needs to be checked by narrowing scope, recent change, a...ReviewedSecurityBeginner14 minFreeSECURITY-052ACME HTTP-01 renewal failsTLS worked yesterday, but automated renewal now fails because the well-known challenge route is treated like an untrusted request pattern by the current edge policy.SecurityIntermediate20 minFreeSECURITY-152A browser isolation policy renders the admin portal remotely, but a direct-download allowlist still lets CSV exports bypass the isolated sessionThe riskiest interaction is protected, yet a side path still leaks the sensitive payload.SecurityIntermediate16 minFreeSECURITY-077Custom WAF allow rule matches but a later managed rule still blocks the requestThe operator sees the expected custom rule fire, yet traffic remains blocked because the final decision is made by a later managed rule with stronger action priority.SecurityIntermediate16 minFreeSECURITY-064WAF bot challenge protects the browser path but blocks webhook callbacks from non-browser clientsThe site is safer for humans, but an integration silently breaks because the challenged path now assumes browser behavior that the webhook sender never provides.SecurityIntermediate17 minFreeSECURITY-131A CSP report-only endpoint loops back through the same proxy path and turns a small XSS burst into an internal traffic floodDetection remains enabled, but the reporting path amplifies rather than observes the incident.SecurityIntermediate15 minFreeSECURITY-270Browser isolation covers the main admin page while websocket upgrades to the same host bypass the isolated route during a failover rehearsalThe most visible path is protected and a less visible interactive path is not. Normal traffic masked the issue until the standby or alternate path became active under rehearsal conditions.SecurityIntermediate17 minFreeSECURITY-028CSP header blocks internal admin tool script after hardeningCSP header blocks internal admin tool script is a hands-on troubleshooting drill. A new browser security policy helps overall, but one internal tool script source was never added and breaks the page. Azure Identity and Access Management needs to be checked by narrowing scope,...SecurityBeginner13 minFreeSECURITY-013Security group allows HTTPS but blocks OCSP responder pathThe application endpoint is reachable, yet revocation or trust verification fails because outbound checks cannot complete.SecurityBeginner15 minFreeSECURITY-022TLS redirect loop created by mixed secure proxy headersTLS redirect loop created by mixed secure proxy headers is a hands-on troubleshooting drill. Security hardening intends to force HTTPS, but conflicting proxy headers produce an endless redirect path. TLS and Certificate Chain needs to be checked by narrowing scope, recent chan...SecurityBeginner15 minFreeSECURITY-108The endpoint protection tool quarantines a sidecar binary and the readiness probe keeps restarting the pod during every deployDeployment health collapses even though the image passed scanning, because the runtime agent removes a file the container still needs after start.SecurityIntermediate16 minFreeSECURITY-098CloudFront signed cookie scope excludes the websocket upgrade host and only the browser terminal loses authStatic pages load normally, but the interactive browser tool fails because the signed cookie domain or path does not cover the upgraded endpoint host.SecurityAdvanced16 minProSECURITY-387A mutual TLS edge validates the client certificateA mutual TLS edge validates the client certificate focuses on TLS and Certificate Chain and asks the reader to isolate Certificate Trust Failure in NGINX. 실무에서는 auth-and-session-failure 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. TLS 관점의...SecurityAdvanced17 minProSECURITY-375A reverse proxy or isolation layer protects browser trafficA reverse proxy or isolation layer protects browser traffic focuses on WAF and AppSec Controls and asks the reader to isolate Permission Denied in NGINX. 실무에서는 permission-denied 경보만 보는 대신 자산 범위, 권한 변경 이력, 인증서나 정책 만료, 우회 경로 존재 여부를 같이 확인해야 대응 우선순위를 제대로 잡을 수 있습니다. WAF / AppSec 관점...SecurityAdvanced17 minProSECURITY-105A WAF bypass exception for health checks accidentally matches the admin route prefix after a path refactorMonitoring stays green, but a protection hole opens because the relaxed path rule now overlaps with privileged endpoints.SecurityAdvanced17 minProSECURITY-143A WAF custom rule matches on decoded path segments, but the reverse proxy evaluates the raw form and one legacy route stays bypassableBoth layers inspect the request, yet they do not interpret the path in the same representation.SecurityAdvanced17 minProSECURITY-092Cloud WAF blocks the admin API path only after a new JSON field increases rule score above thresholdThe endpoint worked before, but the updated payload shape now trips a scoring-based rule model that was previously below the block threshold.SecurityAdvanced17 minPro