Website Security & Threat Management
How Cloudflare security responded to Log4j 2 vulnerability

How Cloudflare security responded to Log4j 2 vulnerability

12/11/2021 · Rushil Shah, Thomas Calderon

What this post added

This post details Cloudflare's internal response to the Log4j2 vulnerability (CVE-2021-44228). It outlines the process of identifying vulnerable systems (ElasticSearch, LogStash, Bitbucket), applying mitigation strategies (removing JndiLookup class, setting system property), and reviewing external reports. It also describes the internal investigation using asset inventory, code scanning, log analysis, network analytics, and endpoint analysis to confirm no compromise. The post highlights the effectiveness of defense-in-depth strategies like restricting outbound traffic and using Cloudflare Access for internal services.

Read the original post ↗