Barracuda WAF-as-a-Service Updates

Security Advisory

by Vishal Khandelwal
We are hardening WAF-as-a-Service to protect against two design limitations and associated vulnerabilities, discovered in the previous firmware. When an application is in Block mode, under certain configurations is may be possible to
New
Announcement
Improvement
Fix

Datapath Upgrade to Version 12.1

by Scott Treacy
We are pleased to announce that we will be upgrading the current datapath from version 12.0 to version 12.1 for all WAF-as-a-Service customers who have Let Barracuda manage my datapath version selected within their WAF-as-a-Service account
Announcement
Datapath

Shared IP deployments are now live

by Scott Treacy
Announcement
Datapath
We are pleased to announce that Shared IP addressing has now been deployed. All new applications will now use a Shared IP address by default. If your account is licenced with a Application Protection Premium plan or your legacy licence

Change to WAF-as-a-Service IP Addresses and Domain Routing

by Nitzan Miron
Announcement
Datapath
In our ongoing effort to optimize the performance, scalability, and reliability of WAF-as-a-Service, we are making some changes to IP addressing of WAF-as-a-Service applications. Starting in 30 days, we will begin migration of many

OpenSSL Upgrade

by Scott Treacy
Announcement
Datapath
Per our Datapath policies, we are informing you that we will be upgrading the version of OpenSSL used in Barracuda WAF-as-a-Service to version 3.0 because version 1.1.1 will become End-of-Life on September 11th 2023. The release notes are

Connectivity Tests

by Scott Treacy
Announcement
Improvement
Datapath
For the version 12.1 datapath, we have deployed an enhanced ability to test connectivity from the WAF-as-a-Service Datapath to the backend application server(s) that you define in the SERVERS page by clicking on a Test Connectivity

Datapath v12.1

by Scott Treacy
We have released Datapath v12.1 into the production environment and this is currently available for manual selection for customer accounts licensed to allow this. The release notes are available here. Information on managing the datapath
Announcement
Datapath

OpenSSL Vulnerabilities (CVE-2023-0286, CVE-2022-4304, CVE-2022-4203, CVE-2023-0215, CVE-2022-4450, CVE-2023-0216, CVE-2023-0217 and CVE-2023-0401)

by Scott Treacy
Announcement
CVE
OpenSSL have announced a new security advisory. Please see Barracuda Campus for the latest news on this advisory.

Datapath Management Fix

by Scott Treacy
A few customers experienced an issue with the logic that manages the scaling of the datapath under certain conditions. We have implemented and tested a fix which will be deployed to the version 11 datapath on Sunday 22nd and the version 12
Fix
Datapath