Cloudflare Patches Flaw Allowing Access to Other Customers' Disk Data
Headline by Prism · from 1 report
Cloudflare patched a vulnerability that allowed customers to access residual disk data left behind by other containers.
1 of 32 monitored outlets · 1 report · English · checked
The Hacker NewsThe brief
Written by software from the 1 report below.
- A flaw in Cloudflare's container infrastructure allowed new containers to read data remaining on storage blocks from previously deleted containers.
- The issue stemmed from a configuration error where storage blocks were not wiped before reallocation.
- Cloudflare resolved the problem by enabling data wiping and clearing existing cache and container disks.
- No evidence indicates this flaw was exploited by anyone other than the researchers who discovered it.
What to watch next
- Duration of exposure while the unsafe setting was active
- Confirmation of impacts on additional services like Browser Run
The points restate the reports; where one says why it matters, that is Prism's reading, not a reported fact.
Coverage
1 outlet
English national1
All filed from India
NamedUnited States · Accomplish · Cloudflare · Linux · Oren Yomtov
The 1 report is listed beside the record.
Corrections and versions
A correction says what was wrong and why. Every earlier headline and brief of this record is kept.
Something wrong?
Say what, and it arrives with this record's address filled in. A correction is welcome.
Ask this story
Answers cite the 1 report above, or say they can't.