Barracuda WAF-as-a-Service Updates

Security Advisory

by Vishal Khandelwal
We are hardening WAF-as-a-Service to protect against two design limitations and associated vulnerabilities, discovered in the previous firmware. When an application is in Block mode, under certain configurations is may be possible to
New
Announcement
Improvement
Fix

Datapath Management Fix

by Scott Treacy
A few customers experienced an issue with the logic that manages the scaling of the datapath under certain conditions. We have implemented and tested a fix which will be deployed to the version 11 datapath on Sunday 22nd and the version 12
Fix
Datapath

Resolved Datapath v10.1 to v11 upgrade issue

by Scott Treacy
After the upgrade of a particular customer from Datapath v10.1 to Datapath v11 we have uncovered a configuration edge case that caused the updated configuration to be pushed to the existing datapath before deployment of Datapath v11 (or
Datapath
Fix
Improvement

Apex DNS Resoloution issue

by Scott Treacy
The DNS resolution issue with WAF-as-a-Service has been resolved. This issue was related to a general DNS issue with Ubuntu instances in Azure. Full details are avaliable here https://bugs.launchpad.net/ubuntu/+source/systemd/+bug/1988119.
Fix

Management layer maintainence

by Scott Treacy
After the rollout of the new Response Pages component earlier this week, we uncovered an edge case where some customers with an existing Custom Block Page were having issues with the special value macros. In order to deploy a fix for these
Fix

URL Normalization, minor features and bugfixes

by Nitzan Miron,
Today we released some minor features, bugfixes and support-assisted features. New features: The URL Normalization component allows you to customize how WAF-as-a-Service processes and decodes URLs. You can now control which SSL protocols
Announcement
Improvement
Fix

Some improvements and bug fixes

by Nitzan Miron,
Today we made some minor improvements to WAF-as-a-Service: Edit Server dialog box: Improved organization of controls Improved cross-validation between controls Added more SSL controls: turn SNI on and off, turn specific SSL protocols on and
Improvement
Fix