Website Security & Threat Management
Cloudflare customers are protected from the Atlassian Confluence CVE-2022-26134

Cloudflare customers are protected from the Atlassian Confluence CVE-2022-26134

6/3/2022 · Reid Tatoris, Daniel Stinson-Diess, Sourov Zaman, Vaibhav Singhal

What this post added

This post details the emergency response to CVE-2022-26134, a critical RCE vulnerability in Atlassian Confluence. Cloudflare engineers analyzed the vulnerability, prepared a WAF mitigation rule, and deployed it within hours of Atlassian's advisory. The rule (IDs 100531 and 408cff2b) was deployed at 23:38 UTC on June 2, 2022, with a default BLOCK action, protecting all WAF customers, including free tier users, running self-hosted Confluence. Additionally, Cloudflare Access provided protection by verifying authenticated users before requests reached the Confluence server.

Read the original post ↗