Fortinet-all_rules SQL-Injection-02 false positive caused an outage!
Hi there,
We use the Fortinet-all_rules rule for our AWS WAF (via AWS Marketplace) and have used it for a long time.
Today, we experienced an unfortunate outage due to the SQL-Injection-02 rule falsely identifying legitimate traffic to a critical endpoint in our system.
This outage was not related to any activity on our part, and AWS eventually confirmed for us that other AWS customers also experienced problems due to this false positive.
Is it the case that Fortinet pushed a problematic update to this ruleset today? The outage began for us at 2:51pm ET. Does that line up with a deploy to that ruleset?
Thanks,
Terren
