Cloudflare Zero-day: Accessing Any Host Globally
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A zero-day vulnerability in Cloudflare's WAF allowed attackers to bypass security rules and access origin servers globally through the /.well-known/acme-challenge/ path. The vulnerability exploited the ACME HTTP-01 certificate validation mechanism, exposing protected origins despite WAF protections. Cloudflare has since patched
•1m read time• From fearsoff.org
Sort: