February 28, 2017 By Mark Samuels 2 min read

Customer data could be at risk after a bug at content delivery specialist Cloudflare spilled private information from its clients online. The bug, which was caused by a memory link in a broken HTML parser chain, was discovered accidentally by Google security specialist Tavis Ormandy. It was fixed quickly, but there are fears the problem could have led to information leaks.

Any leak presents a significant risk to businesses integrity, but it also provides a useful reminder on the importance of security best practice. Experts suggested IT managers should reflect on the news and respond proactively to keep their organizations safe.

Leak Threatens Customer Data

According to the Cloudflare blog, Ormandy contacted the firm after seeing corrupted webpages returned by HTTP requests run through Cloudflare.

The problem arose because Cloudflare’s edge servers were running past the end of a buffer and returning memory that contained private information, such as HTTP cookies and authentication tokens. The impact of the incident was increased by the fact that some leaked customer data had been cached by search engines.

Cloudfare CTO John Graham-Cumming said the greatest period of impact was between Feb. 13 and 18, when about 1 in every 3,300,000 HTTP Cloudflare requests led to memory leakage. He estimated that the leakage represented roughly 0.00003 percent of all requests.

Cloudfare’s Response

The bug may have been leaking customer data to the web for months. Ormandy reported on Chromium that he discovered a broad range of personal information, including private messages from dating sites, full messages from chat services and online password manager data.

Once alerted, Cloudflare took quick reactive steps to fix the leak. The firm turned off features that used the HTML parser chain that caused the bug. And in more good news, the SSL private keys of customers were not leaked.

Cloudflare has worked with search engines around the world to remove leaked information from cached pages. However, the long-term effects of the leak are difficult to judge. Cloudflare clients, which include e-commerce sites, government organizations and finance firms, could face pressure to talk about the extent of their exposure, noted InfoWorld.

How Should IT Managers React?

Ormandy praised Cloudflare for its rapid response to the issue. However, IT managers and end users should be aware of the potential risk of exposure. They should consider proactive action immediately before the consequences of the leak become apparent.

Infosecurity Magazine quoted SkyHigh Networks CTO Kaushik Narayan, who suggested that the Cloudflare incident is a timely reminder to IT managers about the importance of secure passwords. Narayan’s research estimated 99.7 percent of companies have at least one employee who has used a potentially vulnerable application.

Security specialist Shuman Ghosemajumder suggested to Infosecurity Magazine that almost any password on more than 4 million websites could have been compromised because of the Cloudflare incident. The safest action, as laborious as it might seem, is to act as if a compromise has taken place and to change all account passwords immediately.

More from

FYSA – Adobe Cold Fusion Path Traversal Vulnerability

2 min read - Summary Adobe has released a security bulletin (APSB24-107) addressing an arbitrary file system read vulnerability in ColdFusion, a web application server. The vulnerability, identified as CVE-2024-53961, can be exploited to read arbitrary files on the system, potentially leading to unauthorized access and data exposure. Threat Topography Threat Type: Arbitrary File System Read Industries Impacted: Technology, Software, and Web Development Geolocation: Global Environment Impact: Web servers running ColdFusion 2021 and 2023 are vulnerable Overview X-Force Incident Command is monitoring the disclosure…

What does resilience in the cyber world look like in 2025 and beyond?

6 min read -  Back in 2021, we ran a series called “A Journey in Organizational Resilience.” These issues of this series remain applicable today and, in many cases, are more important than ever, given the rapid changes of the last few years. But the term "resilience" can be difficult to define, and when we define it, we may limit its scope, missing the big picture.In the age of generative artificial intelligence (gen AI), the prevalence of breach data from infostealers and the near-constant…

Airplane cybersecurity: Past, present, future

4 min read - With most aviation processes now digitized, airlines and the aviation industry as a whole must prioritize cybersecurity. If a cyber criminal launches an attack that affects a system involved in aviation — either an airline’s system or a third-party vendor — the entire process, from safety to passenger comfort, may be impacted.To improve security in the aviation industry, the FAA recently proposed new rules to tighten cybersecurity on airplanes. These rules would “protect the equipment, systems and networks of transport…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today