Website Security & Threat Management
Cloudflare's Handling of an RCE Vulnerability in cdnjs

Cloudflare's Handling of an RCE Vulnerability in cdnjs

7/24/2021 · Jonathan Ganz, Thomas Calderon, Sven Sauleau

What this post added

This post details Cloudflare's response to a Remote Code Execution (RCE) vulnerability discovered in cdnjs, a platform that utilizes Cloudflare's services. It highlights Cloudflare's rapid incident response, including blocking exploitation, revoking credentials, and investigating potential abuse. The post also outlines the remediation efforts, which involved fixing path traversal issues, implementing AppArmor profiles, and a complete redesign of the auto-update pipeline using a microservices architecture with sandboxed Docker containers to enhance security and prevent future vulnerabilities.

Read the original post ↗