
9/8/2021 · Michael Tremante
What this post added
This post details Cloudflare's rapid response to the Atlassian Confluence OGNL injection vulnerability (CVE-2021-26084). It describes the process of analyzing a Proof-of-Concept, developing and deploying a WAF rule with `BLOCK` action within hours of the PoC's release, and protecting customers using the WAF and Cloudflare Access. It also analyzes traffic patterns, showing that malicious probing began days before the PoC was public, and details the types of attacks observed (command injection, request port anomalies, fake bot signatures, OWASP ModSecurity Core Ruleset matches, HTTP request anomalies) before the specific WAF rule was deployed.