Blind SSRF on platform.dash.cloudflare.com Due to Sentry misconfiguration
Low
C
Cloudflare Public Bug Bounty
Submitted None
Team Summary
Official summary from Cloudflare Public Bug Bounty
Cloudflare uses Sentry for application monitoring and error tracking. Due to the tool's misconfiguration (source code scraping feature enabled), it was possible to sent blind requests to any endpoints using the Cloudflare infrastructure. The issue has been fixed by the Engineering team and the source code fetching feature was disabled in Sentry.
Actions:
Reported by
lohigowda
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Server-Side Request Forgery (SSRF)