Cloudflare bug leaks personal info from 120,000 sites

Hackers are not exploiting 'Cloudbleed' flaw, says CTO

Cloudflare has been leaking personal information, passwords and software keys from over 120,000 sites and services onto the internet, the company has revealed.

The leak was due to a bug in the systems of the company, which offers anti-DDoS and CDN services for around six million websites, and affected companies such as Uber, OKCupid, Fitbit and more.

Advertisement - Article continues below

Discovered by Google security researcher Tavis Ormandy, the bug - which has already been dubbed 'Cloudbleed' after the Heartbleed openSSL vulnerability discovered in 2014 - is apparently a buffer overflow issue and has been blamed on malformed HTML code.

"In some unusual circumstances," Cloudflare CTO John Graham-Cumming wrote in a blog post detailing the issue, "our edge servers were running past the end of a buffer and returning memory that contained private information such as HTTP cookies, authentication tokens, HTTP POST bodies, and other sensitive data. And some of that data had been cached by search engines."

In layman's terms, this meant that users visiting Cloudflare-hosted sites could wind up with data from other sites embedded in their browser. So, someone visiting the Fitbit site could end up accidentally gathering data from another person's OKCupid activity.

The leak was most active from 13 February to 18 February, Graham-Cumming said, affecting around 120,000 sites per day. It may also have been active since 22 September 2016.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Graham-Cumming has said that the issue is now fixed and cached data largely removed from search engines such as Google, adding that he does not believe that the leaked information has been exploited by hackers.

Ormandy kept a running log of the incident, from initial discovery all the way to resolution and public disclosure, including examples of some of the data that was being exposed by the issue.

"We fetched a few live samples, and we observed encryption keys, cookies, passwords, chunks of POST data and even HTTPS requests for other major cloudflare-hosted sites from other users," he wrote. "We've discovered (and purged) cached pages that contain private messages from well-known services, PII from major sites that use Cloudflare, and even plaintext API requests from a popular password manager that were sent over https (!!)."

"The examples we're finding are so bad, I cancelled some weekend plans to go into the office on Sunday to help build some tools to cleanup. I've informed Cloudflare what I'm working on. I'm finding private messages from major dating sites, full messages from a well-known chat service, online password manager data, frames from adult video sites, hotel bookings. We're talking full https requests, client IP addresses, full responses, cookies, passwords, keys, data, everything."

While Cloudflare says it's confident that the information is not being exploited, some security experts are warning that accounts hosted on any site that uses Cloudflare could be compromised, and that users may want to change their account details and passwords.

Image credit: Tavis Ormandy

Featured Resources

The case for a marketing content hub

Transform your digital marketing to deliver customer expectations

Download now

Fast, flexible and compliant e-signatures for global businesses

Be at the forefront of digital transformation with electronic signatures

Download now

Why CEOS should care about the move to SAP S/4HANA

And how they can accelerate business value

Download now

IT faces new security challenges in the wake of COVID-19

Beat the crisis by learning how to secure your network

Download now
Advertisement

Recommended

Visit/software/video-conferencing/355410/zoom-50-adds-256-bit-encryption-and-ui-refresh
video conferencing

Zoom 5.0 adds 256-bit encryption to address security concerns

23 Apr 2020
Visit/security/hacking/355382/whatsapps-flaw-shoulder-surfing
hacking

WhatsApp flaw leaves users open to 'shoulder surfing' attacks

21 Apr 2020
Visit/security/cyber-security/355368/microsoft-builds-ai-to-detect-security-flaws-with-99-accuracy
cyber security

Microsoft AI can detect security flaws with 99% accuracy

20 Apr 2020
Visit/security/vulnerability/355276/businesses-brace-for-second-fujiwhara-effect-of-2020-as-patch-tuesday
vulnerability

Businesses brace for second 'Fujiwhara effect' of 2020 as Patch Tuesday looms

9 Apr 2020

Most Popular

Visit/mobile/5g/355712/nokia-5g-speed-record
5G

Nokia breaks 5G record with speeds nearing 5Gbps

20 May 2020
Visit/cloud/cloud-computing/355742/microsoft-launches-public-cloud-service-for-health-care
cloud computing

Microsoft launches public cloud service for health care

21 May 2020
Visit/software/video-conferencing/355596/house-of-commons-to-ditch-zoom
video conferencing

House of Commons to ditch Zoom in favour of British alternative

11 May 2020