Skip to Main Content
Security & Privacy

Clever and “Shellshock”

September 30, 2014 Dan Carroll

Clever’s Response to the “Shellshock” Security Issue

Recently, a critical security issue was discovered and disclosed to the larger community. This issue, nicknamed Shellshock, could have allowed an attacker to take control of certain systems using specially crafted HTTP requests. The vulnerability came from a flaw in Bash, a tool used by the majority of Internet web servers, including some of Clever’s machines.

Even though we had no reason to believe that any of our services were directly vulnerable, we immediately took action on Wednesday, September 24th to completely secure all of our systems. Our developers worked around the clock to apply fixes as soon as they became available, typically within an hour of release.

We have investigated our systems for evidence of any attempts to exploit this vulnerability and found no such evidence. We will continue watching “Shellshock” closely, and continue to scan for malicious attempts to access Clever’s systems.

If you’d like more general information about “Shellshock”, please read more on the Clever engineering blog.

More to read

Year in review: Diversity, equity, and inclusion in 2024
Company

December 17, 2024

Year in review: Diversity, equity, and inclusion in 2024

A snapshot of our learnings around DE&I for 2024 – our focuses, our progress, and where we need to improve.

Diversity Report 2024
Company

December 13, 2024

Diversity Report 2024

Discover Clever’s 2024 Diversity Report with insights from Amie Ninh, Head of DE&I and L&D. Explore our workforce diversity data, DE&I efforts, and ongoing commitment to building an inclusive, equitable workplace that reflects the schools we serve.

Welcoming Texas-based Dominic Via as Clever’s VP of Sales
Company Districts

August 9, 2024

Welcoming Texas-based Dominic Via as Clever’s VP of Sales

Learn about the major challenges Dominic Via is seeing for K-12 leaders, the latest successes in Texas schools, and upcoming trends that will impact school districts this year.

Subscribe to our Cybersecure K-12 Newsletter to receive exclusive insights to safeguard school data.

This field is for validation purposes and should be left unchanged.