Take over subdomains of r2.dev using R2 custom domains
Team Summary
Official summary from Cloudflare Public Bug Bounty
The Cloudflare R2 Custom Domain feature could be used to take over any subdomain of r2.dev without being verified. The Cloudflare Custom Domain feature allows the customer to configure a CNAME pointing to the r2.dev bucket URL. This attack was possible due to lack of domain validation when the user adds a domain to the account. A control has been implemented to verify that the R2 Custom Domain added has been verified and belongs to the same Cloudflare account. After investigation, it was concluded that there is no evidence of abuse of this issue by anyone other than the researcher and there was no impact to any customer.
Vulnerability Details
Technical details and impact analysis
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Bounty
$1125.00