
9/5/2018 · Richard Sommerville
What this post added
This post details the immediate mitigation of the Apache Struts S2-057 vulnerability by Cloudflare's Web Application Firewall (WAF). It explains the nature of OGNL expressions used in RCE payloads and how S2-057 differs from previous Struts vulnerabilities by exploiting the 'namespace' parameter. Cloudflare's WAF was updated with specific rules to block these attacks, leveraging general OGNL signature rules and targeted payload vector rules. The post also shares observed attack patterns, including probing and attempts to execute commands.