
12/11/2021 · Rushil Shah, Thomas Calderon
What this post added
This post details Cloudflare's internal response to the Log4j2 vulnerability (CVE-2021-44228). It outlines the process of identifying vulnerable systems (ElasticSearch, LogStash, Bitbucket), applying mitigation strategies (removing JndiLookup class, setting system property), and reviewing external reports. It also describes the internal investigation using asset inventory, code scanning, log analysis, network analytics, and endpoint analysis to confirm no compromise. The post highlights the effectiveness of defense-in-depth strategies like restricting outbound traffic and using Cloudflare Access for internal services.