
10/8/2021 · Michael Tremante
What this post added
This post details how Cloudflare's Web Application Firewall (WAF) and URL normalization features provided protection against CVE-2021-41773, a zero-day path traversal vulnerability in Apache HTTP Server. It explains the vulnerability's mechanism, which involves missing path normalization logic, and provides specific WAF rule IDs and descriptions that mitigate the exploit. The post also includes observed exploit attempts and emphasizes the importance of layered security measures.