DEV Community

Cover image for Cloudflare Patches Cross-Tenant Data Exposure Flaw in Containers Service
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Cloudflare Patches Cross-Tenant Data Exposure Flaw in Containers Service

Summary

Cloudflare resolved a cross-tenant data exposure vulnerability in its Containers service that allowed Workers Paid customers to recover residual data from previous tenants. The flaw is caused by a storage configuration that skipped zeroing reused disk blocks, potentially exposing databases, browser profiles, and credentials.

Take Action:

If you use Cloudflare Containers or Sandboxes, there's nothing you need to patch. Cloudflare has already fixed the leak for everyone. As a precaution, if your containers held passwords, API keys or .env files on disk, rotate those secrets, and in future avoid storing credentials on container disks by using a proper secrets manager. And make note of this flaw for your vendor evaluation


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)