Support Article
Multiple CSRF alerts on running out-of-the-box activities
SA-53218
Summary
Multiple Cross-Site Request Forgery (CSRF) alerts occur in Pega Predictive Diagnostic Cloud (PDC) when running out-of-the-box activities.
Error Messages
Not Applicable.
Steps to Reproduce
Unknown.
Root Cause
A defect or configuration issue in the operating environment. The false positive for CSRF attack detected was blocked : URLAccessDetail CSRFAttack Invalid harness ID.
Resolution
Perform the following local-change:- Create a dynamic system setting with the following Ruleset/Key/Value:
Owning Ruleset: Pega-Engine
Key / Setting Purpose: prconfig/security/urlaccessmode/default
Value: allow - Restart the JVM
Published July 23, 2018 - Updated October 8, 2020
Have a question? Get answers now.
Visit the Collaboration Center to ask questions, engage in discussions, share ideas, and help others.