CloudBleed

For discussions about security.
Post Reply
Message
Author
labbe5
Posts: 2159
Joined: Wed 13 Nov 2013, 14:26
Location: Canada

CloudBleed

#1 Post by labbe5 »

https://github.com/pirate/sites-using-cloudflare

Murga-Linux is not in this list.

It turned out that in some unusual circumstances, which I’ll detail below, our edge servers were running past the end of a buffer and returning memory that contained private information such as HTTP cookies, authentication tokens, HTTP POST bodies, and other sensitive data. And some of that data had been cached by search engines.

The bug was serious because the leaked memory could contain private information and because it had been cached by search engines. We have also not discovered any evidence of malicious exploits of the bug or other reports of its existence.
Source : https://blog.cloudflare.com/incident-re ... arser-bug/

Further reading :
https://tutanota.com/blog/posts/cloudbleed

Post Reply