Session mismatch leading to potential account takeover (local access required)
Medium
C
Cloudflare Public Bug Bounty
Submitted None
Team Summary
Official summary from Cloudflare Public Bug Bounty
Cloudflare Dashboard and Zero Trust Dashboard share the same login mechanism for ease of use, however due to an issue with an old session management implementation, logging out from Cloudflare's Dashboard did not automatically result in the user being logged out from the Zero Trust Dashboard. Cloudflare's Engineering Team have addressed the issue by implementing a new session management system.
Actions:
Reported by
spaced
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Insecure Direct Object Reference (IDOR)