LinkedIn·5 min read

Cloudflare Fixes Critical Flaw Exposing Customers’ Container Data

T
The Cyber Security Hub™
Cloudflare Fixes Critical Flaw Exposing Customers’ Container Data
✦Dive DeeperCreate a free account to unlock

Cloudflare has fixed a vulnerability that allowed paying customers to recover data left behind by other tenants on shared container infrastructure. In its September 24 disclosure, the company said it found no evidence of malicious exploitation in available historical telemetry and that customers need take no action.

The issue, detailed in Cloudflare’s incident report , affected the separation between customers’ stored data. It highlights how the security of hosted computing depends on what happens to storage after a workload finishes, as well as the protections surrounding it while it runs.

In Accomplish’s account of the discovery , principal security researcher Oren Yomtov said the team found a disk isolation flaw that allowed a sandbox to read other customers’ files. The reported material included directory listings, SQLite databases, Chromium profiles, environment configuration files and credential files.

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
✦

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in