Origin IP address disclosure through Pingora response header
Medium
C
Cloudflare Public Bug Bounty
Submitted None
Team Summary
Official summary from Cloudflare Public Bug Bounty
HTTP responses to cached files served by the Pingora proxy revealed Origin IP address information. An attacker could trigger this misbehaviour by crafting a request with a malformed Range header. The attack was successful under conditions where Cloudflare cache was in REVALIDATED state, the incoming request was served by Pingora proxy and the affected server accepted the Range header. The issue was remediated by Cloudflare Engineering team and the leaked information was removed from all responses of the proxy.
Actions:
Reported by
smither
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Information Exposure Through an Error Message