Loading HuntDB...

Session mismatch leading to potential account takeover (local access required)

Medium
C
Cloudflare Public Bug Bounty
Submitted None

Team Summary

Official summary from Cloudflare Public Bug Bounty

Cloudflare Dashboard and Zero Trust Dashboard share the same login mechanism for ease of use, however due to an issue with an old session management implementation, logging out from Cloudflare's Dashboard did not automatically result in the user being logged out from the Zero Trust Dashboard. Cloudflare's Engineering Team have addressed the issue by implementing a new session management system.

Reported by spaced

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Insecure Direct Object Reference (IDOR)