Loading HuntDB...

Blind SSRF on platform.dash.cloudflare.com Due to Sentry misconfiguration

Low
C
Cloudflare Public Bug Bounty
Submitted None

Team Summary

Official summary from Cloudflare Public Bug Bounty

Cloudflare uses Sentry for application monitoring and error tracking. Due to the tool's misconfiguration (source code scraping feature enabled), it was possible to sent blind requests to any endpoints using the Cloudflare infrastructure. The issue has been fixed by the Engineering team and the source code fetching feature was disabled in Sentry.

Reported by lohigowda

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Server-Side Request Forgery (SSRF)