Website Security & Threat Management
CVE-2021-44228 - Log4j RCE 0-day mitigation

CVE-2021-44228 - Log4j RCE 0-day mitigation

12/10/2021 · Gabriel Gabor, Andre Bluehs

What this post added

This post details the immediate deployment of three new Cloudflare WAF rules (IDs 100514, 100515, 100516) to mitigate the Log4j RCE vulnerability (CVE-2021-44228). The rules inspect HTTP headers, body, and URL for exploit attempts, with a default action of BLOCK. It also provides context on the vulnerability and mitigation strategies for users not using Cloudflare WAF.

Read the original post ↗