22.8 Cloudbleed
In 2017, Tavis Ormandy, a vulnerability researcher in Google’s Project Zero team, reported a security vulnerability in Cloudflare’s edge servers [76]. Cloudflare is a large Content Delivery Network (CDN) that operates a global network of servers that cache and deliver website content to end users from the server location closest to them.
Because of the vulnerability, the software running on Cloudflare’s edge servers – more precisely, an HTML parser – was reading past the end of a buffer and returning contents from the servers’ internal memory such as HTTP cookies, authentication tokens, and the bodies of HTTP POST requests.
Cloudflare reported that during the peak time, a period of about five days, 1 in every 3,300,000 HTTP requests to Cloudflare’s edge servers potentially resulted in a memory leak [76].
The proof of concept by Tavis Ormandy returned private messages from major dating sites, full messages from...