IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Cloudflare bug leaks personal info from 120,000 sites

Hackers are not exploiting 'Cloudbleed' flaw, says CTO

Cloudflare has been leaking personal information, passwords and software keys from over 120,000 sites and services onto the internet, the company has revealed.

The leak was due to a bug in the systems of the company, which offers anti-DDoS and CDN services for around six million websites, and affected companies such as Uber, OKCupid, Fitbit and more.

Discovered by Google security researcher Tavis Ormandy, the bug - which has already been dubbed 'Cloudbleed' after the Heartbleed openSSL vulnerability discovered in 2014 - is apparently a buffer overflow issue and has been blamed on malformed HTML code.

"In some unusual circumstances," Cloudflare CTO John Graham-Cumming wrote in a blog post detailing the issue, "our edge servers were running past the end of a buffer and returning memory that contained private information such as HTTP cookies, authentication tokens, HTTP POST bodies, and other sensitive data. And some of that data had been cached by search engines."

In layman's terms, this meant that users visiting Cloudflare-hosted sites could wind up with data from other sites embedded in their browser. So, someone visiting the Fitbit site could end up accidentally gathering data from another person's OKCupid activity.

The leak was most active from 13 February to 18 February, Graham-Cumming said, affecting around 120,000 sites per day. It may also have been active since 22 September 2016.

Graham-Cumming has said that the issue is now fixed and cached data largely removed from search engines such as Google, adding that he does not believe that the leaked information has been exploited by hackers.

Ormandy kept a running log of the incident, from initial discovery all the way to resolution and public disclosure, including examples of some of the data that was being exposed by the issue.

"We fetched a few live samples, and we observed encryption keys, cookies, passwords, chunks of POST data and even HTTPS requests for other major cloudflare-hosted sites from other users," he wrote. "We've discovered (and purged) cached pages that contain private messages from well-known services, PII from major sites that use Cloudflare, and even plaintext API requests from a popular password manager that were sent over https (!!)."

"The examples we're finding are so bad, I cancelled some weekend plans to go into the office on Sunday to help build some tools to cleanup. I've informed Cloudflare what I'm working on. I'm finding private messages from major dating sites, full messages from a well-known chat service, online password manager data, frames from adult video sites, hotel bookings. We're talking full https requests, client IP addresses, full responses, cookies, passwords, keys, data, everything."

While Cloudflare says it's confident that the information is not being exploited, some security experts are warning that accounts hosted on any site that uses Cloudflare could be compromised, and that users may want to change their account details and passwords.

Image credit: Tavis Ormandy

Featured Resources

The state of Salesforce: Future of business

Three articles that look forward into the changing state of Salesforce and the future of business

Free Download

The mighty struggle to migrate SAP to the cloud may be over

A simplified and unified approach to delivering Enterprise Transformation in the cloud

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

The Total Economic Impact™ Of IBM FlashSystem

Cost savings and business benefits enabled by FlashSystem

Free Download

Recommended

Ten ways to protect your company from the next big data breach
data breaches

Ten ways to protect your company from the next big data breach

18 Feb 2022
Gumtree site code made personal data of users and sellers publicly accessible
data protection

Gumtree site code made personal data of users and sellers publicly accessible

16 Dec 2021
Pizza chain exposed 100,000 employees' Social Security numbers
data breaches

Pizza chain exposed 100,000 employees' Social Security numbers

19 Nov 2021
83% of critical infrastructure companies have experienced breaches in the last three years
cyber security

83% of critical infrastructure companies have experienced breaches in the last three years

11 Nov 2021

Most Popular

How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

29 Jul 2022
Samsung proposes 11 Texas semiconductor plants worth $191 billion
Hardware

Samsung proposes 11 Texas semiconductor plants worth $191 billion

21 Jul 2022
Should you take your password manager off the internet?
Sponsored

Should you take your password manager off the internet?

28 Jul 2022