
3/1/2017 · Matthew Prince
What this post added
This post details the analysis and mitigation of the 'Cloudbleed' vulnerability, which involved a parser bug causing memory leaks of customer data, including headers and cookies, onto web pages. The analysis focused on quantifying the impact, identifying the root cause in a new parser version triggered by specific HTML flaws and enabled features, and investigating potential malicious exploitation through log data review. The findings indicated no evidence of malicious exploitation before patching and limited data leakage for the majority of customers.