Mitigating Log4Shell in Azure Environments

Following up on Log4Shell, here is how to protect Azure resources.

Azure WAF

If you use Azure Front Door or Application Gateway, Microsoft has updated the WAF rulesets to block JNDI lookup patterns. Ensure your WAF is in Prevention mode.

Workloads

Check your HDInsight, Spring Cloud, and Event Hubs (Kafka) instances. Microsoft is patching managed services, but you are responsible for any containers or VMs you run.


Discover more from C4: Container, Code, Cloud & Context

Subscribe to get the latest posts sent to your email.

Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.