Cloudflare Fixes Critical Cross-Tenant Flaw in Containers Service

Vulnerability Could Have Allowed Customers to Access Residual Data from Other Users' Containers

By LineZotpaper
Published
Read Time2 min
Cloudflare has patched a vulnerability in its Containers and Sandboxes services that could have allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host, potentially exposing sensitive files such as credentials and databases.

Cloudflare has addressed a cross-tenant vulnerability in its Containers and Sandboxes services, which could have let malicious actors read residual data from other customers' containers. The flaw, reported via HackerOne on September 4 by security researcher Oren Yomtov at Accomplish, affected Cloudflare Containers—a service available on the Workers Paid plan that enables developers to run containerized applications on Cloudflare's infrastructure.

The issue stemmed from a shared storage pool that was configured to skip zeroing reused 64 KiB blocks. When a container's root disk was deleted, its physical blocks were returned to a pool serving multiple customer accounts. By writing only 4 KiB to an unused region of a new container's disk, an attacker could trigger the allocation of a reused 64 KiB block. Without zeroing, only the 4 KiB write would overwrite the block, leaving the remaining 60 KiB readable and potentially containing data from previous users.

Researchers found residual material on 18 of 24 container placements and across 20 of 22 underlying nodes tested, including directory listings, SQLite databases, Chromium profiles, .env files, and credential files. Cloudflare noted that a successful exploit would cross the tenant-isolation boundary, potentially disclosing filesystem metadata, directory structures, database pages, and application data. However, the attacker would not have control over the victim or host, nor could they read an actively attached disk.

Cloudflare stated that the researchers only used scripts performing checks and returning aggregate counts, not actual disk contents, so no real customer data was exposed during the evaluation. The researchers also did not demonstrate any ability to change or disrupt other customers' workloads.

The company removed the setting causing skipped block zeroing, retired existing container disks, and cleared cached snapshots that may have contained old mappings. All mitigation actions were completed by September 19, and Cloudflare found no evidence of customer data exposure through logs, telemetry, or historical data. The fixes were applied automatically, requiring no action from customers.

§

Analysis

Why This Matters

  • Data Security Risk: The flaw exposed sensitive customer data like credentials and databases, highlighting the risks of multi-tenant cloud infrastructure.
  • Trust in Cloud Services: Incidents like this can erode trust in cloud providers' ability to maintain tenant isolation, especially for services handling sensitive workloads.
  • Industry Implications: The discovery underscores the importance of proper storage pool management and zeroing practices to prevent cross-tenant data leaks.

Background

Cloudflare is a major content delivery network and cloud services provider, offering a range of edge computing products including Workers and Containers. Multi-tenant environments inherently rely on strong isolation mechanisms to prevent one customer from accessing another's data. Storage block reuse is a common optimization technique but must be handled carefully to avoid residual data exposure. The vulnerability was discovered through a bug bounty program on HackerOne, which encourages external security research.

Key Perspectives

  • Cloudflare: Emphasized that no customer data was actually exposed and that the fix was applied automatically. They removed the problematic setting and retired affected disks, stating logs show no exploitation.
  • Security Researchers (Accomplish): Demonstrated a practical attack that could recover sensitive files from other customers, showing the risk was real even if not exploited in the wild.
  • Customers: While Cloudflare says no action is needed, this incident may prompt users to review data storage practices and consider encryption for sensitive data in cloud environments.

What to Watch

  • Audit findings: Any further reports from Cloudflare or independent audits confirming the fix's effectiveness.
  • Regulatory scrutiny: Potential investigations by data protection authorities if customer data was indeed exposed.
  • Industry response: Whether other cloud providers review their own storage zeroing practices in light of this vulnerability.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.