Unmasking the top exploited vulnerabilities of 2022
The blog post discusses the top 10 most exploited CVEs (Common Vulnerabilities and Exposures) of 2022 according to Cloudflare's data, with Log4J vulnerability being the first on their list. It highlights that due to its high impact, all plans on Cloudflare are provided WAF Managed Rules for free to protect against such threats. Other CVEs mentioned in this post include Atlassian Confluence Code Injection (CVE-2022-26134), Microsoft Exchange SSRF and RCE vulnerabilities, F5 BIG-IP Command Injection (CVE-2022-1388), VMware Workspace ONE Access and Identity Manager Server-side Template Injection Remote Code Execution Vulnerability (CVE-2022-22954), Confluence Server Webwork OGNL injection (CVE-2021-26084). The article emphasizes the importance of keeping software updated and utilizing WAF Managed Rules for protection against these vulnerabilities. It also mentions that Enterprise customers have access to additional AI-powered detection features in their WAF implementation.
Company
Cloudflare
Date published
Aug. 4, 2023
Author(s)
Himanshu Anand, Sabina Zejnilovic, Daniele Molteni
Word count
1402
Language
English
Hacker News points
2