-
A flaw in Cloudflare Containers lets one customer’s container pull up leftover data from someone else’s old workload.
-
Researchers recovered database files, browser profiles, and login credentials in most of their tests, according to Accomplish.
-
Cloudflare says it fixed the bug fully and found no proof that anyone actually stole customer data.
A security flaw in Cloudflare Containers put customer data at risk on shared servers. Cloudflare Containers run workloads for many different customers on the same infrastructure. Sharing infrastructure this way helps companies save on costs and resources. But it also means customers depend on strict separation between different workloads.
The bug let one customer’s container recover data left behind by another customer’s old workload. Cloudflare and security researchers at Accomplish confirmed the issue together. Cloudflare shared the news publicly on September 24. The company said it fixed the flaw completely. Cloudflare also said it found no proof that customers’ data went missing.
Details of the Cloudflare Security Flaw
Oren Yomtov from Accomplish found the bug first. He reported it through Cloudflare’s bug bounty program on September 4. Bug bounty programs pay researchers for reporting security problems responsibly. The flaw involved how Cloudflare’s shared storage system handled deleted containers.
One can reuse old disk blocks without wiping them clean first. This lets a brand new container pull up bytes from an earlier customer’s files. Those leftover bytes stayed readable even after removing the original workload.
Accomplish researchers tested this bug across 24 different production containers. They recovered leftover data in 18 of those tests. That means the method worked in most of their attempts. The recovered files included directory structures and database pages.
Researchers also found SQLite databases, Chromium browser profiles, and .env files. Some of the recovered files held credential-related information too. Files like these often store passwords, tokens, or private settings. Losing access to files like these could expose sensitive account details.
Cloudflare stated that the exposed data came from old, unused disk space. According to Cloudflare, an attacker cannot specify the scope of data to be obtained. Hence, the leaks were random and not targeted at a specific individual.
How the Storage Bug Actually Worked
The true issue originated in the Linux device-mapper thin provisioning system, responsible for the provision of storage. Cloudflare’s storage solution chose to split the storage disk into blocks of 64 kilobytes each. Some configuration options prevented wiping the newly used blocks.
The researchers were able to demonstrate that writing a small amount of new data would cause the blocks to start being reused. Old blocks would be reused while keeping a portion of readable data. This meant that newer containers would occasionally recover old lost files, creating a small technical issue with real-world implications.
Once Cloudflare learned about the problem, the company implemented the block-wiping procedure for all newly provisioned storage. The researchers tried the solution on September 14 and confirmed that the proof of concept no longer functioned. However, previously mapped disks and cached layers still created a potential risk.
The company then decommissioned active container disks completely and erased all affected caches during maintenance periods Cloudflare additionally rebooted its devices to accomplish the cleaning process. The business made a statement that the entire cleanup was concluded on September 19.
Cloudflare’s Repair and Public Reactions
After resolving the software error, Cloudflare proceeded to another step. The corporation examined carefully its previous recordings of the disk activity. The objective was to get any signs of utilization of this technique beforehand.
The company has detected some activities of Accomplish researchers tied to this investigation. It also managed to identify activities executed by its own engineers who performed authorized tests. The company has declared that they detected not a single case of this technique usage by any third parties.
The news led to reactions from the security experts in the X social network. The user named 90S KID, posting as @epochster, expressed doubts on the statement of Cloudflare about the absence of the disrespectful activity.
The user reminded that the researchers recovered real credentials during the experiment. He also pointed out that it is generally complicated to investigate any utilization of the shared disk systems in the retrospect way.
These reactions reflect a larger concern regarding multi-tenant cloud systems as a whole. Cloudflare has also faced other security concerns involving potential bypass techniques, including the threat actor releasing alleged Cloudflare Turnstile bypass code on a cybercrime forum.
An issue doesn’t necessarily require the release of confidential data to pose danger to the safety of users. The residual information kept on shared servers could cause serious privacy violations on its own.
This danger may exist even when no proof of hacking is present. A lot of companies depend on cloud-based solutions used during their working hours. A problem with shared storage may affect several clients at the same time.
According to Cloudflare, customers don’t have to do anything. Cloudflare confirmed a full fix of the vulnerability in all of its systems. The company keeps an eye on its infrastructure, searching for similar issues.