
3/31/2022 · Michael Tremante, Himanshu Anand
What this post added
This post details the deployment of new managed WAF rules to mitigate the Spring4Shell vulnerabilities (CVE-2022-22947, CVE-2022-22950, CVE-2022-22963, CVE-2022-22965). It specifies the WAF rule IDs and legacy IDs for rules targeting CVE-2022-22947 ('Spring - CVE:CVE-2022-22947'), CVE-2022-22950 and CVE-2022-22963 ('PHP - Code Injection' and 'Plone - Dangerous File Extension'), and CVE-2022-22963 and CVE-2022-22965 ('Spring - Code Injection'). It also mentions the use of OWASP Core Ruleset for protection.