跳转到内容
搜索文档

历史记录(2024)

最后更新 查看 MarkdownAgent 设置

托管规则集更新

规则集规则 ID旧版规则 ID描述更改日期旧动作新动作
Cloudflare Specials100675Adobe ColdFusion - Auth Bypass - CVE:CVE-2023-382052024-10-21LogBlock
Cloudflare Specials100676Palo Alto Networks - Auth Bypass - CVE:CVE-2024-59102024-10-21LogBlock
Cloudflare Specials100677SolarWinds - Auth Bypass - CVE:CVE-2024-289872024-10-21LogBlock
Cloudflare Specials100673GoAnywhere - Remote Code Execution - CVE:CVE-2023-06692024-10-14LogBlock
Cloudflare Specials100669

Apache HugeGraph-Server - Remote Code Execution - CVE:CVE-2024-27348

2024-10-07LogBlock
Cloudflare Specials100672Ivanti Virtual Traffic Manager - Auth Bypass - CVE:CVE-2024-75932024-10-07LogBlock
Cloudflare Specials100670Junos - Remote Code Execution - CVE:CVE-2023-368442024-10-07LogBlock
Cloudflare Specials100671Microsoft SQL Server - Remote Code Execution - CVE:CVE-2020-06182024-10-07LogBlock
Cloudflare Specials100581Joomla - Information Disclosure - CVE:CVE-2023-237522024-10-07LogBlock
Cloudflare Specials100668

Progress Software WhatsUp Gold - Information Disclosure - CVE:CVE-2024-6670

2024-10-01LogBlock
Cloudflare SpecialsN/AAnomaly:Body - Large 22024-09-16N/ADisabled
Cloudflare Specials100526VMware vCenter - CVE:CVE-2022-22954, CVE:CVE-2022-229482024-09-03N/ABlock
Cloudflare Specials100667Authentik - Auth Bypass - CVE:CVE-2024-42490Emergency, 2024-08-20N/ABlock
Cloudflare Specials100666Apache OFBiz - Remote Code Execution - CVE:CVE-2024-321132024-08-19LogBlock
Cloudflare Specials100665Zoho ManageEngine - Remote Code Execution - CVE:CVE-2023-290842024-08-19LogBlock
Cloudflare Specials100664Automation Anywhere - SSRF - CVE:CVE-2024-69222024-08-05LogBlock
Cloudflare Specials100663WSO2 - Dangerous File Upload - CVE:CVE-2022-294642024-08-05LogBlock
Cloudflare Specials100662

ServiceNow - Input Validation - CVE:CVE-2024-4879, CVE:CVE-2024-5178, CVE:CVE-2024-5217

2024-08-05LogBlock
Cloudflare Specials100659Common Payloads for Server-side Template Injection - Base642024-07-29N/ADisabled
Cloudflare Specials100559APrototype Pollution - Common Payloads - Base642024-07-29N/ADisabled
Cloudflare Specials100660Server-side Includes - Common Payloads - Base642024-07-29N/ADisabled
Cloudflare Specials100661SQLi - Common Payloads - Base642024-07-29N/ADisabled
Cloudflare Specials100524Java - Remote Code Execution2024-07-29BlockDisabled
Cloudflare Specials100524Java - Remote Code Execution2024-07-24LogBlock
Cloudflare Specials100659Common Payloads for Server-side Template Injection2024-07-24N/ADisabled
Cloudflare Specials100533AGeneric Payloads NoSQL Injection Base64 Beta2024-07-24N/ADisabled
Cloudflare Specials100533AGeneric Payloads NoSQL Injection2024-07-24N/ADisabled
Cloudflare Specials100644Generic Payloads XSS Base64 Beta2024-07-24N/ADisabled
Cloudflare Specials100644Generic Payloads XSS2024-07-24N/ADisabled
Cloudflare Specials100642LDAP Injection Base64 Beta2024-07-24N/ADisabled
Cloudflare Specials100642LDAP Injection2024-07-24N/ADisabled
Cloudflare Specials100559APrototype Pollution - Common Payloads2024-07-24N/ADisabled
Cloudflare Specials100645Remote Code Execution - Generic Payloads2024-07-24N/ADisabled
Cloudflare Specials100660Server-Side Includes - Common Payloads2024-07-24N/ADisabled
Cloudflare Specials100661SQLi - Common Payloads2024-07-24N/ADisabled
Cloudflare Specials100658Apache OFBiz - SSRF - CVE:CVE-2023-509682024-07-17LogBlock
Cloudflare Specials100657JEECG - Deserialization - CVE:CVE-2023-494422024-07-17LogBlock
Cloudflare Specials100532Vulnerability scanner activity2024-07-17LogBlock
Cloudflare Specials100654

Telerik Report Server - Auth Bypass - CVE:CVE-2024-4358, CVE:CVE-2024-1800

2024-07-10LogBlock
Cloudflare Specials100655

Rejetto HTTP File Server - Remote Code Execution - CVE:CVE-2024-23692

2024-07-10LogBlock
Cloudflare Specials100647pgAdmin - Remote Code Execution - CVE:CVE-2024-31162024-07-10LogBlock
Cloudflare Specials100656MoveIT - Auth Bypass - CVE:CVE-2024-58062024-07-10LogBlock
Cloudflare Specials100079AJava - Deserialization - 22024-07-10LogBlock
Cloudflare Specials100648Groovy - Remote Code Execution2024-07-10LogBlock
Cloudflare Specials100700Apache SSRF vulnerability CVE-2021-404382024-07-10LogBlock
Cloudflare Specials100652PHP CGI - Information Disclosure - CVE:CVE-2024-4577Emergency, 2024-06-18N/ABlock
Cloudflare Specials100653

Veeam Backup Enterprise Manager - Information Disclosure - CVE:CVE-2024-29849

Emergency, 2024-06-18N/ABlock
Cloudflare Specials100651Atlassian Confluence - Remote Code Execution - CVE:CVE-2024-21683Emergency, 2024-06-06N/ABlock
Cloudflare Specials100650

Check Point Security - Information Disclosure - CVE:CVE-2024-24919

Emergency, 2024-05-30N/ABlock
Cloudflare Specials100649

FortiSIEM - Remote Code Execution - CVE:CVE-2024-23108, CVE:CVE-2023-34992

Emergency, 2024-05-29N/ABlock
Cloudflare SpecialsN/AGeneric Payloads XSS Base64 2 Beta2024-05-21N/ADisabled
Cloudflare SpecialsN/AGeneric Payloads NoSQL Injection Base64 Beta2024-05-14N/ADisabled
Cloudflare SpecialsN/ALDAP Injection Base64 Beta2024-05-14N/ADisabled
Cloudflare SpecialsN/ANoSQL - Injection Base64 2 Beta2024-05-14N/ADisabled
Cloudflare SpecialsN/AGeneric Payloads XSS Base64 Beta2024-05-08N/ADisabled
Cloudflare Specials100532Vulnerability scanner activity2024-05-06N/ABlock
Cloudflare Specials100533NoSQL - Injection2024-05-06N/ABlock
Sensitive Data Disclosure (SDD)N/AMalaysian Phone Number2024-04-24N/ADisabled
Sensitive Data Disclosure (SDD)N/A Malaysia Identification Card Number2024-04-24N/ADisabled
Cloudflare SpecialsN/AVulnerability scanner activity 3 Base64 Beta2024-04-24N/ADisabled
Cloudflare SpecialsN/ADefault Windows User - Directory Traversal Base64 Beta2024-04-24N/ADisabled
Cloudflare SpecialsN/AGeneric Payloads NoSQL Injection Base64 Beta2024-04-24N/ADisabled
Cloudflare SpecialsN/ANoSQL - Injection Base64 2 Beta2024-04-24N/ADisabled
Cloudflare SpecialsN/ALDAP Injection Base64 Beta2024-04-24N/ADisabled
Cloudflare Specials100645Remote Code Execution - Generic Payloads2024-04-22N/ADisabled
Cloudflare Specials100533AGeneric Payloads NoSQL Injection2024-04-22N/ADisabled
Cloudflare Specials100644Generic Payloads XSS2024-04-22N/ADisabled
Cloudflare Specials100007C_BETA

Command Injection - Common Attack Commands Beta

已更新检测逻辑。

2024-04-22N/ADisabled
Cloudflare Specials100643

Default Windows User - Directory Traversal

已更新检测逻辑。

2024-04-22N/ADisabled
Cloudflare Specials100642

LDAP Injection

已更新检测逻辑。

2024-04-22N/ADisabled
Cloudflare Specials100532C

Vulnerability scanner activity 3

已更新检测逻辑。

2024-04-22N/ADisabled
Cloudflare Specials100007CCommand Injection - Common Attack CommandsEmergency, 2024-04-16N/ABlock
Cloudflare Specials100045C

Anomaly:URL:Path - Multiple Slashes, Relative Paths, CR, LF or NULL 2

2024-04-15N/ADisabled
Cloudflare Specials100007C_BETACommand Injection - Common Attack Commands Beta2024-04-15N/ADisabled
Cloudflare Specials100643Default Windows User - Directory Traversal2024-04-15N/ADisabled
Cloudflare Specials100088EGeneric XXE Attack2024-04-15N/ADisabled
Cloudflare Specials100088DGeneric XXE Attack 22024-04-15N/ADisabled
Cloudflare Specials100536AGraphQL Introspection2024-04-15N/ADisabled
Cloudflare Specials100536BGraphQL SSRF2024-04-15N/ADisabled
Cloudflare Specials100642LDAP Injection2024-04-15N/ADisabled
Cloudflare Specials100532CVulnerability scanner activity 32024-04-15N/ADisabled
Cloudflare Specials100632Nginx - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100633PHP - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100634Generic Database - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100635Generic Log - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100636Generic Webservers - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100637Generic Home Directory - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100638Generic System Process - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100639Command Injection2024-04-08N/ADisabled
Cloudflare Specials100640Generic System - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100641Apache - File Inclusion2024-04-08N/ADisabled
Cloudflare Specials100629

JetBrains TeamCity - Auth Bypass, Remote Code Execution - CVE:CVE-2024-27198, CVE:CVE-2024-27199

2024-03-18N/ABlock
Cloudflare Specials100630

Apache OFBiz - Auth Bypass, Remote Code Execution - CVE:CVE-2023-49070, CVE:CVE-2023-51467

2024-03-18N/ABlock
Cloudflare Specials100627

Wordpress:Plugin:Bricks Builder Theme - Command Injection - CVE:CVE-2024-25600

2024-03-11N/ABlock
Cloudflare Specials100628ConnectWise - Auth Bypass2024-03-11N/ABlock
Cloudflare Specials100135DXSS - JS On Events2024-03-04N/ABlock
Cloudflare Specials100546XSS - HTML Encoding2024-02-26N/ABlock
Cloudflare Specials100622B, 100622C

Ivanti - Command Injection - CVE:CVE-2023-46805, CVE:CVE-2024-21887, CVE:CVE-2024-22024

2024-02-20N/ABlock
Cloudflare SpecialsN/AMicrosoft ASP.NET - Code Injection - Function response.write2024-02-20N/ABlock
Cloudflare SpecialsN/ANoSQL, MongoDB - SQLi - Comparison2024-02-20N/ABlock
Cloudflare SpecialsN/ANoSQL, MongoDB - SQLi - Expression2024-02-20N/ABlock
Cloudflare SpecialsN/APHP - Code Injection2024-02-20N/ADisabled
Cloudflare SpecialsN/A

PHP, vBulletin, jQuery File Upload - Code Injection, Dangerous File Upload - CVE:CVE-2018-9206, CVE:CVE-2019-17132

2024-02-20N/ABlock
Cloudflare Specials100625Jenkins - Information Disclosure - CVE:CVE-2024-238972024-02-12N/ABlock
Cloudflare Specials100514Log4j Headers2024-02-12N/ABlock
Cloudflare Specials100515BLog4j Body Obfuscation2024-02-12N/ABlock
Cloudflare Specials100624GoAnywhere - Auth Bypass - CVE:CVE-2024-02042024-02-05N/ABlock
Cloudflare Specials100626,100626AAnomaly:Header:Content-Type - Multiple2024-02-05N/ADisabled
Cloudflare SpecialsN/AAngularJS - XSS2024-02-05N/ABlock
Cloudflare SpecialsN/AApache HTTP Server - Server-Side Includes2024-02-05N/ADisabled
Cloudflare SpecialsN/ACommand Injection - CVE:CVE-2014-62712024-02-05N/ABlock
Cloudflare SpecialsN/ACommand Injection - Nslookup2024-02-05N/ABlock
Cloudflare SpecialsN/AMicrosoft ASP.NET - Code Injection2024-02-05N/ADisabled
Cloudflare Specials100623Atlassian Confluence - Template Injection - CVE:CVE-2023-22527Emergency, 2024-01-22N/ABlock
Cloudflare Specials100622

Ivanti - Auth Bypass, Command Injection - CVE:CVE-2023-46805, CVE:CVE-2024-21887

Emergency, 2024-01-17N/ABlock
Cloudflare Specials100620Microsoft ASP.NET - Remote Code Execution - CVE:CVE-2023-358132024-01-16N/ABlock
Cloudflare Specials100619Liferay - Remote Code Execution - CVE:CVE-2020-79612024-01-16N/ABlock
Cloudflare Specials100618pfSense - Remote Code Execution - CVE:CVE-2023-423262024-01-16N/ABlock
Cloudflare Specials100621Clerk - Auth Bypass2024-01-16N/ADisabled
Cloudflare Specials100612SnakeYAML - CVE:CVE-2022-14712024-01-04N/ABlock

常规更新

2024-12-18

改进的 VPN Managed List

客户现在可以有效管理被识别为来自 VPN IP 的传入流量。有合规限制的客户现在可以更好地遵守当地法律法规。有 CDN 限制的客户可使用改进的 VPN Managed List,防止用户试图绕过地理限制的未授权访问。借助新的 VPN Managed List 增强功能,客户可以改善整体安全态势,减少对不良或恶意流量的暴露。

2024-12-10

更改 IP Lists 中列表项的顺序(适用于 API 和 Terraform 用户)

由于 API 实现的变更,通过 API 或 Terraform 获取的 IP 列表中列表项的顺序可能会变化,这可能导致 Terraform 检测到状态变更。要解决此问题,请重新同步 Terraform 状态,或将 Terraform Cloudflare provider 升级到 version 4.44.0 或更高版本。

2024-11-14

Security Events 分页

修复了 Security Events 采样日志中分页的问题,此前部分页面会缺失数据。同时从事件日志中移除了总数,因为这些仅为采样日志。

2024-11-04

Security Analytics 和 Security Events 中的新表格

在 Security Analytics 和 Security Events 中切换到了新的、响应更灵敏的表格。

2024-08-29

修复偶发的攻击分数不匹配

修复了导致全局 WAF attack score 与子分数之间分数不匹配的问题。在某些情况下,子分数高于预期(非攻击),而全局攻击分数低于预期(攻击),从而导致误报。

2024-05-23

改进的检测能力

WAF attack score 现在会自动检测并解码 HTTP 请求中的 Base64 和 JavaScript(Unicode 转义序列)。此更新面向所有可使用 WAF attack score 的客户(可使用单个字段的 Business 客户以及 Enterprise 客户)。

这篇文档对您有帮助吗?