Website Security & Threat Management
How Cloudflare helped mitigate the Atlassian Confluence OGNL vulnerability before the PoC was released

How Cloudflare helped mitigate the Atlassian Confluence OGNL vulnerability before the PoC was released

9/8/2021 · Michael Tremante

What this post added

This post details Cloudflare's rapid response to the Atlassian Confluence OGNL injection vulnerability (CVE-2021-26084). It describes the process of analyzing a Proof-of-Concept, developing and deploying a WAF rule with `BLOCK` action within hours of the PoC's release, and protecting customers using the WAF and Cloudflare Access. It also analyzes traffic patterns, showing that malicious probing began days before the PoC was public, and details the types of attacks observed (command injection, request port anomalies, fake bot signatures, OWASP ModSecurity Core Ruleset matches, HTTP request anomalies) before the specific WAF rule was deployed.

Read the original post ↗