Cloudflare fixes Containers cross-tenant flaw exposing customer data

Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare fixed a Containers and Sandboxes flaw that could let Workers Paid customers recover leftover data from other tenants’ containers on the same physical host. The issue affected reused storage blocks and could expose files, databases, Chromium profiles, and credential data, but Cloudflare found no evidence of real customer data exposure. #Cloudflare #WorkersPaid #Containers #Sandboxes

Keypoints

  • Cloudflare patched a data exposure flaw in Containers and Sandboxes.
  • The bug could reveal residual data from other tenants on the same host.
  • Exposed files could include SQLite databases, .env files, and credential files.
  • The issue came from reused 64 KiB blocks that were not zeroed.
  • Cloudflare found no evidence that customer data was actually exposed.

Read More: https://www.bleepingcomputer.com/news/security/cloudflare-fixes-containers-cross-tenant-flaw-exposing-customer-data/