diff --git a/src/content/docs/waf/change-log/2025-05-27.mdx b/src/content/docs/waf/change-log/2025-05-27.mdx new file mode 100644 index 000000000000000..2b34a1a7001bcbd --- /dev/null +++ b/src/content/docs/waf/change-log/2025-05-27.mdx @@ -0,0 +1,145 @@ +--- +title: "2025-05-27" +type: table +pcx_content_type: release-notes +sidebar: + order: 788 +tableOfContents: false +--- + +import { RuleID } from "~/components"; + +This week’s roundup covers nine vulnerabilities, including six critical RCEs and one dangerous file upload. Affected platforms span cloud services, CI/CD pipelines, CMSs, and enterprise backup systems. Several are now addressed by updated WAF managed rulesets. + +**Key Findings** + +- Ingress-Nginx (CVE-2025-1098): Unauthenticated RCE via unsafe annotation handling. Impacts Kubernetes clusters. +- GitHub Actions (CVE-2025-30066): RCE through malicious workflow inputs. Targets CI/CD pipelines. +- Craft CMS (CVE-2025-32432): Template injection enables unauthenticated RCE. High risk to content-heavy sites. +- F5 BIG-IP (CVE-2025-31644): RCE via TMUI exploit, allowing full system compromise. +- AJ-Report (CVE-2024-15077): RCE through untrusted template execution. Affects reporting dashboards. +- NAKIVO Backup (CVE-2024-48248): RCE via insecure script injection. High-value target for ransomware. +- SAP NetWeaver (CVE-2025-31324): Dangerous file upload flaw enables remote shell deployment. +- Ivanti EPMM (CVE-2025-4428, 4427): Auth bypass allows full access to mobile device management. +- Vercel (CVE-2025-32421): Information leak via misconfigured APIs. Useful for attacker recon. + +**Impact** + +These newly detected vulnerabilities introduce critical risk across modern web stacks, AI infrastructure, and content platforms: unauthenticated RCEs in Commvault, BentoML, and Craft CMS enable full system compromise with minimal attacker effort. + +Apache HTTPD information leak can support targeted reconnaissance, increasing the success rate of follow-up exploits. Organizations using these platforms should prioritize patching and monitor for indicators of exploitation using updated WAF detection rules. + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + +
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed Ruleset + + 100746Vercel - Information DisclosureLogDisabledThis is a New Detection
Cloudflare Managed Ruleset + + 100754AJ-Report - Remote Code Execution - CVE:CVE-2024-15077LogBlockThis is a New Detection
Cloudflare Managed Ruleset + + 100756NAKIVO Backup - Remote Code Execution - CVE:CVE-2024-48248LogBlockThis is a New Detection
Cloudflare Managed Ruleset + + 100757Ingress-Nginx - Remote Code Execution - CVE:CVE-2025-1098LogDisabledThis is a New Detection
Cloudflare Managed Ruleset + + 100759SAP NetWeaver - Dangerous File Upload - CVE:CVE-2025-31324LogBlockThis is a New Detection
Cloudflare Managed Ruleset + + 100760Craft CMS - Remote Code Execution - CVE:CVE-2025-32432LogBlockThis is a New Detection
Cloudflare Managed Ruleset + + 100761GitHub Action - Remote Code Execution - CVE:CVE-2025-30066LogDisabledThis is a New Detection
Cloudflare Managed Ruleset + + 100762Ivanti EPMM - Auth Bypass - CVE:CVE-2025-4428, CVE:CVE-2025-4427LogBlockThis is a New Detection
Cloudflare Managed Ruleset + + 100763F5 Big IP - Remote Code Execution - CVE:CVE-2025-31644LogDisabledThis is a New Detection
diff --git a/src/content/docs/waf/change-log/scheduled-changes.mdx b/src/content/docs/waf/change-log/scheduled-changes.mdx index 7a26c859752ef30..ba3604fb7a61465 100644 --- a/src/content/docs/waf/change-log/scheduled-changes.mdx +++ b/src/content/docs/waf/change-log/scheduled-changes.mdx @@ -25,102 +25,58 @@ import { RSSButton, RuleID } from "~/components"; - 2025-05-19 - 2025-05-26 + 2025-05-27 + 2025-06-02 Log - 100746 + 100764 - + - Vercel - Information Disclosure + Versa Concerto SD-WAN - Auth Bypass - CVE:CVE-2025-34027 This is a New Detection - 2025-05-19 - 2025-05-26 + 2025-05-27 + 2025-06-02 Log - 100754 - - - - AJ-Report - Remote Code Execution - CVE:CVE-2024-15077 - This is a New Detection - - - 2025-05-19 - 2025-05-26 - Log - 100756 - - - - NAKIVO Backup - Remote Code Execution - CVE:CVE-2024-48248 - This is a New Detection - - - 2025-05-19 - 2025-05-26 - Log - 100757 - - - - Ingress-Nginx - Remote Code Execution - CVE:CVE-2025-1098 - This is a New Detection - - - 2025-05-19 - 2025-05-26 - Log - 100759 - - - - SAP NetWeaver - Dangerous File Upload - CVE:CVE-2025-31324 - This is a New Detection - - - 2025-05-19 - 2025-05-26 - Log - 100760 - - - - Craft CMS - Remote Code Execution - CVE:CVE-2025-32432 + 100765 + + + + Versa Concerto SD-WAN - Auth Bypass - CVE:CVE-2025-34026 This is a New Detection - 2025-05-19 - 2025-05-26 + 2025-05-27 + 2025-06-02 Log - 100761 + 100766 - + - GitHub Action - Remote Code Execution - CVE:CVE-2025-30066 + Kemp LoadMaster - Remote Code Execution - CVE:CVE-2024-7591 This is a New Detection - 2025-05-19 - 2025-05-26 + 2025-05-27 + 2025-06-02 Log - 100762 + 100767 - + - Ivanti EPMM - Auth Bypass - CVE:CVE-2025-4428, CVE:CVE-2025-4427 + AnythingLLM - SSRF - CVE:CVE-2024-0759 This is a New Detection - 2025-05-19 - 2025-05-26 + 2025-05-27 + 2025-06-02 Log - 100763 + 100768 - + - F5 Big IP - Remote Code Execution - CVE:CVE-2025-31644 + Anyscale Ray - Remote Code Execution - CVE:CVE-2023-48022 This is a New Detection diff --git a/src/content/release-notes/waf.yaml b/src/content/release-notes/waf.yaml index 2cd21e0665f61dd..67fe95701ef25ba 100644 --- a/src/content/release-notes/waf.yaml +++ b/src/content/release-notes/waf.yaml @@ -5,11 +5,14 @@ productLink: "/waf/" productArea: Application security productAreaLink: /fundamentals/reference/changelog/security/ entries: - - publish_date: "2025-05-19" - scheduled_date: "2025-05-26" + - publish_date: "2025-05-27" + scheduled_date: "2025-06-02" individual_page: true scheduled: true link: "/waf/change-log/scheduled-changes/" + - publish_date: "2025-05-27" + individual_page: true + link: "/waf/change-log/2025-05-27/" - publish_date: "2025-05-19" individual_page: true link: "/waf/change-log/2025-05-19/"