
12/10/2021 · Gabriel Gabor, Andre Bluehs
What this post added
This post details the immediate deployment of three new Cloudflare WAF rules (IDs 100514, 100515, 100516) to mitigate the Log4j RCE vulnerability (CVE-2021-44228). The rules inspect HTTP headers, body, and URL for exploit attempts, with a default action of BLOCK. It also provides context on the vulnerability and mitigation strategies for users not using Cloudflare WAF.