
12/15/2021 · Gabriel Gabor, Andre Bluehs
What this post added
Released WAF rules (IDs 100514, 6b1cc72dff9746469d4695a474430f12; 100515, 0c054d4e4dd5455c9ff8f01efe5abb10; 100516, 5f6744fa026a4638bda5b3d7d5e015dd) to block Log4j RCE exploits targeting HTTP headers, body, and URL. Also released an advanced rule (IDs 100517, 2c5413e155db4365befe0df160ba67d7) for broader protection with a higher false positive rate.