<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Changelog · WAF</title><link>https://developers.cloudflare.com/waf/change-log/</link><description>Updates to Cloudflare's WAF product.</description><language>en-us</language><atom:link href="https://developers.cloudflare.com/waf/change-log/index.xml" rel="self"/><lastBuildDate>Tuesday, Nov 21, 2023</lastBuildDate><item><title>2023-11-21</title><link>https://developers.cloudflare.com/waf/change-log/2023-11-21/</link><description>
&lt;table style="width: 100%">
&lt;thead>
&lt;tr>
&lt;th>Ruleset&lt;/th>
&lt;th>Rule ID&lt;/th>
&lt;th>Legacy Rule ID&lt;/th>
&lt;th>Description&lt;/th>
&lt;th>Previous Action&lt;/th>
&lt;th>New Action&lt;/th>
&lt;th>Comments&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...8ed2b1d9&lt;/td>
&lt;td>100611&lt;/td>
&lt;td>WordPress:Plugin:WooCommerce - Unauthorized Administrator Access - CVE:CVE-2023-28121&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...c3b6a372&lt;/td>
&lt;td>100593&lt;/td>
&lt;td>Adobe ColdFusion - Auth Bypass, Remote Code Execution - CVE:CVE-2023-29298, CVE:CVE-2023-38203, CVE:CVE-2023-26360&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description><pubDate>Tuesday, Nov 21, 2023</pubDate></item><item><title>2023-11-06 - Emergency</title><link>https://developers.cloudflare.com/waf/change-log/2023-11-06---emergency-release/</link><description>
&lt;table style="width: 100%">
&lt;thead>
&lt;tr>
&lt;th>Ruleset&lt;/th>
&lt;th>Rule ID&lt;/th>
&lt;th>Legacy Rule ID&lt;/th>
&lt;th>Description&lt;/th>
&lt;th>Previous Action&lt;/th>
&lt;th>New Action&lt;/th>
&lt;th>Comments&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...c54e7046&lt;/td>
&lt;td>100614&lt;/td>
&lt;td>Atlassian Confluence - Code Injection - CVE:CVE-2023-22518&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description><pubDate>Monday, Nov 6, 2023</pubDate></item><item><title>Scheduled changes</title><link>https://developers.cloudflare.com/waf/change-log/scheduled-changes/</link><description>
&lt;table style="width: 100%">
&lt;thead>
&lt;tr>
&lt;th>Announcement Date&lt;/th>
&lt;th>Release Date&lt;/th>
&lt;th>Release Behavior&lt;/th>
&lt;th>Legacy Rule ID&lt;/th>
&lt;th>Rule ID&lt;/th>
&lt;th>Description&lt;/th>
&lt;th>Comments&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>N/A&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>No updates scheduled&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description><pubDate>Monday, Oct 30, 2023</pubDate></item><item><title>2023-10-30</title><link>https://developers.cloudflare.com/waf/change-log/2023-10-30/</link><description>
&lt;table style="width: 100%">
&lt;thead>
&lt;tr>
&lt;th>Ruleset&lt;/th>
&lt;th>Rule ID&lt;/th>
&lt;th>Legacy Rule ID&lt;/th>
&lt;th>Description&lt;/th>
&lt;th>Previous Action&lt;/th>
&lt;th>New Action&lt;/th>
&lt;th>Comments&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...d59a59db&lt;/td>
&lt;td>100609&lt;/td>
&lt;td>Keycloak - SSRF - CVE:CVE-2020-10770&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description><pubDate>Monday, Oct 30, 2023</pubDate></item><item><title>2023-10-23</title><link>https://developers.cloudflare.com/waf/change-log/2023-10-23/</link><description>
&lt;table style="width: 100%">
&lt;thead>
&lt;tr>
&lt;th>Ruleset&lt;/th>
&lt;th>Rule ID&lt;/th>
&lt;th>Legacy Rule ID&lt;/th>
&lt;th>Description&lt;/th>
&lt;th>Previous Action&lt;/th>
&lt;th>New Action&lt;/th>
&lt;th>Comments&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...3e3f706d&lt;/td>
&lt;td>100606&lt;/td>
&lt;td>JetBrains TeamCity - Auth Bypass, Remote Code Execution - CVE:CVE-2023-42793&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...469c4a38&lt;/td>
&lt;td>100607&lt;/td>
&lt;td>Progress WS_FTP - Information Disclosure - CVE:CVE-2023-40044&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...7ccccdce&lt;/td>
&lt;td>100608&lt;/td>
&lt;td>Progress WS_FTP - Remote Code Execution - CVE:CVE-2023-40044&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description><pubDate>Monday, Oct 23, 2023</pubDate></item><item><title>2023-10-11 - Emergency</title><link>https://developers.cloudflare.com/waf/change-log/2023-10-11---emergency-release/</link><description>
&lt;table style="width: 100%">
&lt;thead>
&lt;tr>
&lt;th>Ruleset&lt;/th>
&lt;th>Rule ID&lt;/th>
&lt;th>Legacy Rule ID&lt;/th>
&lt;th>Description&lt;/th>
&lt;th>Previous Action&lt;/th>
&lt;th>New Action&lt;/th>
&lt;th>Comments&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...ec9f34e1&lt;/td>
&lt;td>100604&lt;/td>
&lt;td>Atlassian Confluence - Privilege Escalation - CVE:CVE-2023-22515&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>This rule is released for our Cloudflare Free customers as well, rule ID: ...91935fcb (Detection logic update)&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description><pubDate>Wednesday, Oct 11, 2023</pubDate></item><item><title>2023-10-04 - Emergency</title><link>https://developers.cloudflare.com/waf/change-log/2023-10-04---emergency-release/</link><description>
&lt;table style="width: 100%">
&lt;thead>
&lt;tr>
&lt;th>Ruleset&lt;/th>
&lt;th>Rule ID&lt;/th>
&lt;th>Legacy Rule ID&lt;/th>
&lt;th>Description&lt;/th>
&lt;th>Previous Action&lt;/th>
&lt;th>New Action&lt;/th>
&lt;th>Comments&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...ec9f34e1&lt;/td>
&lt;td>100604,100605&lt;/td>
&lt;td>Atlassian Confluence - Privilege Escalation - CVE:CVE-2023-22515&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>This rule is released for our Cloudflare Free customers as well, rule ID: ...91935fcb&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description><pubDate>Tuesday, Oct 3, 2023</pubDate></item><item><title>2023-10-02</title><link>https://developers.cloudflare.com/waf/change-log/2023-10-02/</link><description>
&lt;table style="width: 100%">
&lt;thead>
&lt;tr>
&lt;th>Ruleset&lt;/th>
&lt;th>Rule ID&lt;/th>
&lt;th>Legacy Rule ID&lt;/th>
&lt;th>Description&lt;/th>
&lt;th>Previous Action&lt;/th>
&lt;th>New Action&lt;/th>
&lt;th>Comments&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...34780914&lt;/td>
&lt;td>100532&lt;/td>
&lt;td>Vulnerability scanner activity&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>This rule was released as 100532_BETA in legacy waf and ...6e298ed7 in new WAF&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description><pubDate>Monday, Oct 2, 2023</pubDate></item><item><title>2023-09-22 - Emergency</title><link>https://developers.cloudflare.com/waf/change-log/2023-09-22---emergency-release/</link><description>
&lt;table style="width: 100%">
&lt;thead>
&lt;tr>
&lt;th>Ruleset&lt;/th>
&lt;th>Rule ID&lt;/th>
&lt;th>Legacy Rule ID&lt;/th>
&lt;th>Description&lt;/th>
&lt;th>Previous Action&lt;/th>
&lt;th>New Action&lt;/th>
&lt;th>Comments&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...066c0c9a&lt;/td>
&lt;td>100602&lt;/td>
&lt;td>Code Injection - CVE:CVE-2023-36845&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...0746d000&lt;/td>
&lt;td>100603&lt;/td>
&lt;td>Information Disclosure - CVE:CVE-2023-28432&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description><pubDate>Friday, Sep 22, 2023</pubDate></item><item><title>2023-09-18</title><link>https://developers.cloudflare.com/waf/change-log/2023-09-18/</link><description>
&lt;table style="width: 100%">
&lt;thead>
&lt;tr>
&lt;th>Ruleset&lt;/th>
&lt;th>Rule ID&lt;/th>
&lt;th>Legacy Rule ID&lt;/th>
&lt;th>Description&lt;/th>
&lt;th>Previous Action&lt;/th>
&lt;th>New Action&lt;/th>
&lt;th>Comments&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...25ba9d7c&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>SSRF Cloud&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Disabled&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description><pubDate>Monday, Sep 18, 2023</pubDate></item><item><title>2023-09-04</title><link>https://developers.cloudflare.com/waf/change-log/2023-09-04/</link><description>
&lt;table style="width: 100%">
&lt;thead>
&lt;tr>
&lt;th>Ruleset&lt;/th>
&lt;th>Rule ID&lt;/th>
&lt;th>Legacy Rule ID&lt;/th>
&lt;th>Description&lt;/th>
&lt;th>Previous Action&lt;/th>
&lt;th>New Action&lt;/th>
&lt;th>Comments&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...c5f041ac&lt;/td>
&lt;td>100597&lt;/td>
&lt;td>Information Disclosure - Path Normalization&lt;/td>
&lt;td>Log&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...50cec478&lt;/td>
&lt;td>100598&lt;/td>
&lt;td>Remote Code Execution - Common Bash Bypass&lt;/td>
&lt;td>Log&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...ec5b0d04&lt;/td>
&lt;td>100599&lt;/td>
&lt;td>Ivanti - Auth Bypass - CVE:CVE-2023-38035&lt;/td>
&lt;td>Log&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...6912c055&lt;/td>
&lt;td>100601&lt;/td>
&lt;td>Malware - Polymorphic Encoder&lt;/td>
&lt;td>Log&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...8242627b&lt;/td>
&lt;td>100146B&lt;/td>
&lt;td>SSRF Local BETA&lt;/td>
&lt;td>Log&lt;/td>
&lt;td>Disabled&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description><pubDate>Monday, Sep 4, 2023</pubDate></item><item><title>2023-08-21</title><link>https://developers.cloudflare.com/waf/change-log/2023-08-21/</link><description>
&lt;table style="width: 100%">
&lt;thead>
&lt;tr>
&lt;th>Ruleset&lt;/th>
&lt;th>Rule ID&lt;/th>
&lt;th>Legacy Rule ID&lt;/th>
&lt;th>Description&lt;/th>
&lt;th>Previous Action&lt;/th>
&lt;th>New Action&lt;/th>
&lt;th>Comments&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...84dadf5a&lt;/td>
&lt;td>100595&lt;/td>
&lt;td>MobileIron - Auth Bypass - CVE:CVE-2023-35082&lt;/td>
&lt;td>Log&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...48a60154&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>SQLi - Keyword + SubExpress + Comment + BETA&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Disabled&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description><pubDate>Monday, Aug 21, 2023</pubDate></item><item><title>2023-08-17 - Emergency</title><link>https://developers.cloudflare.com/waf/change-log/2023-08-17---emergency-release/</link><description>
&lt;table style="width: 100%">
&lt;thead>
&lt;tr>
&lt;th>Ruleset&lt;/th>
&lt;th>Rule ID&lt;/th>
&lt;th>Legacy Rule ID&lt;/th>
&lt;th>Description&lt;/th>
&lt;th>Previous Action&lt;/th>
&lt;th>New Action&lt;/th>
&lt;th>Comments&lt;/th>
&lt;/tr>
&lt;/thead>
&lt;tbody>
&lt;tr>
&lt;td>Cloudflare Specials&lt;/td>
&lt;td>...cac42ce2&lt;/td>
&lt;td>100596&lt;/td>
&lt;td>Citrix Content Collaboration ShareFile - Remote Code Execution - CVE:CVE-2023-24489&lt;/td>
&lt;td>N/A&lt;/td>
&lt;td>Block&lt;/td>
&lt;td>N/A&lt;/td>
&lt;/tr>
&lt;/tbody>
&lt;/table></description><pubDate>Thursday, Aug 17, 2023</pubDate></item></channel></rss>