Cloudflare is not properly deleting user's account
Medium
C
Cloudflare Public Bug Bounty
Submitted None
Team Summary
Official summary from Cloudflare Public Bug Bounty
A vulnerability was discovered in Cloudflare’s User Deletion process which resulted in the current session not being terminated when a request to delete the user had been submitted. Cloudflare’s Engineering Team have fixed the vulnerability and user sessions are now invalidated once a user account deletion request is received.
Actions:
Reported by
csc_
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Business Logic Errors