
9/24/2014 · Ryan Lackey
What this post added
This post details Cloudflare's immediate response to the critical CVE-2014-6271 (Shellshock) vulnerability in Bash. It describes the internal testing and deployment of a patch across Cloudflare's infrastructure to protect its own servers. Additionally, it highlights the proactive creation and default enablement of a Web Application Firewall (WAF) rule for Pro, Business, and Enterprise customers to protect their servers that may not have been patched. The post also notes the subsequent release of updated Bash packages addressing related vulnerabilities (CVE-2014-7169) and Cloudflare's continued monitoring and patching efforts.