Skip to content

Commit e2c49a0

Browse files
vs-mgpedrosousa
andauthored
Release-Apr-01-2025 (#21245)
* Release-Apr-01-2025 * Fix missing quote * Apply suggestions from PCX review --------- Co-authored-by: Pedro Sousa <[email protected]>
1 parent 45e821b commit e2c49a0

File tree

3 files changed

+244
-55
lines changed

3 files changed

+244
-55
lines changed
Lines changed: 235 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,235 @@
1+
---
2+
title: "2025-04-01"
3+
type: table
4+
pcx_content_type: release-notes
5+
sidebar:
6+
order: 794
7+
tableOfContents: false
8+
---
9+
10+
import { RuleID } from "~/components";
11+
12+
<table style="width: 100%">
13+
<thead>
14+
<tr>
15+
<th>Ruleset</th>
16+
<th>Rule ID</th>
17+
<th>Legacy Rule ID</th>
18+
<th>Description</th>
19+
<th>Previous Action</th>
20+
<th>New Action</th>
21+
<th>Comments</th>
22+
</tr>
23+
</thead>
24+
<tbody>
25+
<tr>
26+
<td>Cloudflare Managed Ruleset</td>
27+
<td>
28+
<RuleID id="8b8074e73b7d4aba92fc68f3622f0483" />
29+
</td>
30+
<td>100732</td>
31+
<td>Sitecore - Code Injection - CVE:CVE-2025-27218</td>
32+
<td>Log</td>
33+
<td>Block</td>
34+
<td>This is a New Detection</td>
35+
</tr>
36+
<tr>
37+
<td>Cloudflare Managed Ruleset</td>
38+
<td>
39+
<RuleID id="8350947451a1401c934f5e660f101cca" />
40+
</td>
41+
<td>100733</td>
42+
<td>Angular-Base64-Upload - Remote Code Execution - CVE:CVE-2024-42640</td>
43+
<td>Log</td>
44+
<td>Block</td>
45+
<td>This is a New Detection</td>
46+
</tr>
47+
<tr>
48+
<td>Cloudflare Managed Ruleset</td>
49+
<td>
50+
<RuleID id="a9ec9cf625ff42769298671d1bbcd247" />
51+
</td>
52+
<td>100734</td>
53+
<td>Apache Camel - Remote Code Execution - CVE:CVE-2025-29891</td>
54+
<td>Log</td>
55+
<td>Block</td>
56+
<td>This is a New Detection</td>
57+
</tr>
58+
<tr>
59+
<td>Cloudflare Managed Ruleset</td>
60+
<td>
61+
<RuleID id="3d6bf99039b54312a1a2165590aea1ca" />
62+
</td>
63+
<td>100735</td>
64+
<td>Progress Software WhatsUp Gold - Remote Code Execution - CVE:CVE-2024-4885</td>
65+
<td>Log</td>
66+
<td>Block</td>
67+
<td>This is a New Detection</td>
68+
</tr>
69+
<tr>
70+
<td>Cloudflare Managed Ruleset</td>
71+
<td>
72+
<RuleID id="d104e3246dc14ac7851b4049d9d8c5f2" />
73+
</td>
74+
<td>100737</td>
75+
<td>Apache Tomcat - Remote Code Execution - CVE:CVE-2025-24813</td>
76+
<td>Log</td>
77+
<td>Block</td>
78+
<td>This is a New Detection</td>
79+
</tr>
80+
<tr>
81+
<td>Cloudflare Managed Ruleset</td>
82+
<td>
83+
<RuleID id="21c7a963e1b749e7b1753238a28a42c4" />
84+
</td>
85+
<td>100659</td>
86+
<td>Common Payloads for Server-side Template Injection</td>
87+
<td>N/A</td>
88+
<td>Disabled</td>
89+
<td>N/A</td>
90+
</tr>
91+
<tr>
92+
<td>Cloudflare Managed Ruleset</td>
93+
<td>
94+
<RuleID id="887843ffbe90436dadd1543adaa4b037" />
95+
</td>
96+
<td>100659</td>
97+
<td>Common Payloads for Server-side Template Injection - Base64</td>
98+
<td>N/A</td>
99+
<td>Disabled</td>
100+
<td>N/A</td>
101+
</tr>
102+
<tr>
103+
<td>Cloudflare Managed Ruleset</td>
104+
<td>
105+
<RuleID id="3565b80fc5b541b4832c0fc848f6a9cf" />
106+
</td>
107+
<td>100642</td>
108+
<td>LDAP Injection</td>
109+
<td>N/A</td>
110+
<td>Disabled</td>
111+
<td>N/A</td>
112+
</tr>
113+
<tr>
114+
<td>Cloudflare Managed Ruleset</td>
115+
<td>
116+
<RuleID id="44d7bf9bf0fa4898b8579573e0713e9f" />
117+
</td>
118+
<td>100642</td>
119+
<td>LDAP Injection Base64</td>
120+
<td>N/A</td>
121+
<td>Disabled</td>
122+
<td>N/A</td>
123+
</tr>
124+
<tr>
125+
<td>Cloudflare Managed Ruleset</td>
126+
<td>
127+
<RuleID id="e35c9a670b864a3ba0203ffb1bc977d1" />
128+
</td>
129+
<td>100005</td>
130+
<td>DotNetNuke - File Inclusion - CVE:CVE-2018-9126, CVE:CVE-2011-1892, CVE:CVE-2022-31474</td>
131+
<td>N/A</td>
132+
<td>Block</td>
133+
<td>N/A</td>
134+
</tr>
135+
<tr>
136+
<td>Cloudflare Managed Ruleset</td>
137+
<td>
138+
<RuleID id="cd8db44032694fdf8d6e22c1bb70a463" />
139+
</td>
140+
<td>100527</td>
141+
<td>Apache Struts - CVE:CVE-2021-31805</td>
142+
<td>N/A</td>
143+
<td>Block</td>
144+
<td>N/A</td>
145+
</tr>
146+
<tr>
147+
<td>Cloudflare Managed Ruleset</td>
148+
<td>
149+
<RuleID id="0d838d9ab046443fa3f8b3e50c99546a" />
150+
</td>
151+
<td>100702</td>
152+
<td>Command Injection - CVE:CVE-2022-24108</td>
153+
<td>N/A</td>
154+
<td>Block</td>
155+
<td>N/A</td>
156+
</tr>
157+
<tr>
158+
<td>Cloudflare Managed Ruleset</td>
159+
<td>
160+
<RuleID id="533fbad558ce4c5ebcf013f09a5581d0" />
161+
</td>
162+
<td>100622C</td>
163+
<td>Ivanti - Command Injection - CVE:CVE-2023-46805, CVE:CVE-2024-21887, CVE:CVE-2024-22024</td>
164+
<td>N/A</td>
165+
<td>Block</td>
166+
<td>N/A</td>
167+
</tr>
168+
<tr>
169+
<td>Cloudflare Managed Ruleset</td>
170+
<td>
171+
<RuleID id="04176552f62f4b75bf65981206d0b009" />
172+
</td>
173+
<td>100536C</td>
174+
<td>GraphQL Command Injection</td>
175+
<td>N/A</td>
176+
<td>Disabled</td>
177+
<td>N/A</td>
178+
</tr>
179+
<tr>
180+
<td>Cloudflare Managed Ruleset</td>
181+
<td>
182+
<RuleID id="25883bf28575433c952b830c1651d0c8" />
183+
</td>
184+
<td>100536</td>
185+
<td>GraphQL Injection</td>
186+
<td>N/A</td>
187+
<td>Block</td>
188+
<td>N/A</td>
189+
</tr>
190+
<tr>
191+
<td>Cloudflare Managed Ruleset</td>
192+
<td>
193+
<RuleID id="7b70da1bb8d243bd80cd7a73af00f61d" />
194+
</td>
195+
<td>100536A</td>
196+
<td>GraphQL Introspection</td>
197+
<td>N/A</td>
198+
<td>Disabled</td>
199+
<td>N/A</td>
200+
</tr>
201+
<tr>
202+
<td>Cloudflare Managed Ruleset</td>
203+
<td>
204+
<RuleID id="58c4853c250946359472b7eaa41e5b67" />
205+
</td>
206+
<td>100536B</td>
207+
<td>GraphQL SSRF</td>
208+
<td>N/A</td>
209+
<td>Disabled</td>
210+
<td>N/A</td>
211+
</tr>
212+
<tr>
213+
<td>Cloudflare Managed Ruleset</td>
214+
<td>
215+
<RuleID id="1c241ed5f5bd44b19e17476b433e5b3d" />
216+
</td>
217+
<td>100559A</td>
218+
<td>Prototype Pollution - Common Payloads</td>
219+
<td>N/A</td>
220+
<td>Disabled</td>
221+
<td>N/A</td>
222+
</tr>
223+
<tr>
224+
<td>Cloudflare Managed Ruleset</td>
225+
<td>
226+
<RuleID id="af748489e1c2411d80d855954816b26f" />
227+
</td>
228+
<td>100559A</td>
229+
<td>Prototype Pollution - Common Payloads - Base64</td>
230+
<td>N/A</td>
231+
<td>Disabled</td>
232+
<td>N/A</td>
233+
</tr>
234+
</tbody>
235+
</table>

src/content/docs/waf/change-log/scheduled-changes.mdx

Lines changed: 4 additions & 53 deletions
Original file line numberDiff line numberDiff line change
@@ -25,63 +25,14 @@ import { RSSButton, RuleID } from "~/components";
2525
</thead>
2626
<tbody>
2727
<tr>
28-
<td>2025-03-17</td>
2928
<td>2025-04-01</td>
29+
<td>2025-04-07</td>
3030
<td>Log</td>
31-
<td>100732</td>
31+
<td>100739A</td>
3232
<td>
33-
<RuleID id="8b8074e73b7d4aba92fc68f3622f0483" />
33+
<RuleID id="9209bb65527f4c088bca5ffad6b2d36c" />
3434
</td>
35-
<td>Sitecore - Code Injection - CVE:CVE-2025-27218</td>
36-
<td>This is a New Detection</td>
37-
</tr>
38-
<tr>
39-
<td>2025-03-17</td>
40-
<td>2025-04-01</td>
41-
<td>Log</td>
42-
<td>100733</td>
43-
<td>
44-
<RuleID id="8350947451a1401c934f5e660f101cca" />
45-
</td>
46-
<td>
47-
Angular-Base64-Upload - Remote Code Execution - CVE:CVE-2024-42640
48-
</td>
49-
<td>This is a New Detection</td>
50-
</tr>
51-
<tr>
52-
<td>2025-03-17</td>
53-
<td>2025-04-01</td>
54-
<td>Log</td>
55-
<td>100734</td>
56-
<td>
57-
<RuleID id="a9ec9cf625ff42769298671d1bbcd247" />
58-
</td>
59-
<td>Apache Camel - Remote Code Execution - CVE:CVE-2025-29891</td>
60-
<td>This is a New Detection</td>
61-
</tr>
62-
<tr>
63-
<td>2025-03-17</td>
64-
<td>2025-04-01</td>
65-
<td>Log</td>
66-
<td>100735</td>
67-
<td>
68-
<RuleID id="3d6bf99039b54312a1a2165590aea1ca" />
69-
</td>
70-
<td>
71-
Progress Software WhatsUp Gold - Remote Code Execution -
72-
CVE:CVE-2024-4885
73-
</td>
74-
<td>This is a New Detection</td>
75-
</tr>
76-
<tr>
77-
<td>2025-03-21</td>
78-
<td>2025-04-01</td>
79-
<td>Log</td>
80-
<td>100737</td>
81-
<td>
82-
<RuleID id="d104e3246dc14ac7851b4049d9d8c5f2" />
83-
</td>
84-
<td>Apache Tomcat - Remote Code Execution - CVE:CVE-2025-24813</td>
35+
<td>Next.js - Auth Bypass - CVE:CVE-2025-29927 - 2</td>
8536
<td>This is a New Detection</td>
8637
</tr>
8738
</tbody>

src/content/release-notes/waf.yaml

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,11 +5,14 @@ productLink: "/waf/"
55
productArea: Application security
66
productAreaLink: /fundamentals/reference/changelog/security/
77
entries:
8-
- publish_date: "2025-03-17"
9-
scheduled_date: "2025-04-01"
8+
- publish_date: "2025-04-01"
9+
scheduled_date: "2025-04-07"
1010
individual_page: true
1111
scheduled: true
1212
link: "/waf/change-log/scheduled-changes/"
13+
- publish_date: "2025-04-01"
14+
individual_page: true
15+
link: "/waf/change-log/2025-04-01/"
1316
- publish_date: "2025-03-22"
1417
individual_page: true
1518
link: "/waf/change-log/2025-03-22-emergency/"

0 commit comments

Comments
 (0)