Summary
Cloudflare resolved a cross-tenant data exposure vulnerability in its Containers service that allowed Workers Paid customers to recover residual data from previous tenants. The flaw is caused by a storage configuration that skipped zeroing reused disk blocks, potentially exposing databases, browser profiles, and credentials.
Take Action:
If you use Cloudflare Containers or Sandboxes, there's nothing you need to patch. Cloudflare has already fixed the leak for everyone. As a precaution, if your containers held passwords, API keys or .env files on disk, rotate those secrets, and in future avoid storing credentials on container disks by using a proper secrets manager. And make note of this flaw for your vendor evaluation
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)