Cloudflare CDN Defect Allowed Compromise Of 12% Of All Sites

Share post:

The website security company Cloudflare recently fixed a critical vulnerability in its free and open-source CDNJS, which is expected to affect 12.7% of all websites on the internet.

Security researcher RyotaK discovered the vulnerability by finding a way to fully compromise Cloudflare’s CDNJS by tricking servers into executing arbitrary code.

The vulnerability, if exploited, could lead to a total compromise of the CDNJS infrastructure

After Cloudflare reported the vulnerability, the Cloudflare team took drastic action and worked on several fixes to address the issue.

Although the original solution attempted to fix the symlink vulnerability, the complexity of the CDNJS ecosystem caused further fixes to be made over the following weeks.

CNDJS serves millions of websites with approximately 4,000 publicly available JavaScript and CSS libraries stored publicly on GitHub.

For more information, read the original story in Bleeping Computer.

SUBSCRIBE NOW

Related articles

YouTubers Targeted As Cyberattackers Hide Infostealers in YouTube Comments, Google Search Results

Attackers have found a new way to infect people seeking pirated or cracked software: planting malicious download links...

WordPress Co-Founder Warns Lawsuits Could Kill WordPress.org

WordPress co-founder Matt Mullenweg has warned that ongoing lawsuits stemming from his conflict with hosting provider WP Engine...

New macOS Malware Exploits Apple’s Security Features to Stay Hidden and Steal User Data

A newly discovered variant of the Banshee macOS Stealer malware is putting 100 million Apple users at risk...

Microsoft MFA Outage Blocks Access to Microsoft 365 Apps, Raising Cloud Reliability Concerns

Microsoft faced another significant service disruption over the weekend, with a Multi-Factor Authentication (MFA) outage that blocked users...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways