---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Block Expired Anti-CSRF Tokens \[Updated in Security Center 1.5\]

# Block Expired Anti-CSRF Tokens \[Updated in Security Center 1.5\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Block expired CSRF tokens to prevent cross-site request forgery attacks.

## Overview {#sc-block-expired-csrf-tokens__section_byz_k45_swb}

Cross-site request forgeries are a type of malicious exploit whereby unauthorized commands are performed on behalf of an authenticated user.

## Configuration details {#sc-block-expired-csrf-tokens__section_oxn_w45_swb}

{#sc-block-expired-csrf-tokens__table_mtb_wsf_swb__entry__2}

| Attribute | Description |
|-|-|
| Overview | Controls the usage of an expired secure token to identify and validate incoming requests. Set to false to prevent a previously expired token to validate an incoming request. |
| Configuration name | glide.security.csrf_previous.allow |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | false |
| Default value | true |
| Category | [Access control](https://servicenow-prod.fluidtopics.net/xAmazkRh5FKyeb7q4TQGWw "The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.") |
| Security risk | Severity score: 6.5 |
| Security risk | Severity rating per CVSS score: Medium |
| Security risk | Security risk details: Enforces a strong anti-CSRF mechanism to protect authenticated functionality, and effective anti-automation or anti-CSRF protects unauthenticated functionality. |
| Dependencies and prerequisites | None |
| References | [Enable Anti-CSRF token \[New in Security Center 1.3, updated in 1.5, and removed in 2.0\]](5HnExiYsP8dMZYFTOTUV6w "Use the glide.security.use_csrf_token property to ensure the use of a secure token to identify and validates incoming requests, which in turn are used to prevent these attacks."), [cross-site request forgery](https://en.wikipedia.org/wiki/Cross-site_request_forgery). |
[ ]

{#sc-block-expired-csrf-tokens__table_mtb_wsf_swb}

