Cloudflare flaw could have led to series of supply-chain attacks

Cloudflare flaw could have led to series of supply-chain attacks

Image: Gerd Altmann (cc)




Hackers were able to exploit a path traversal vulnerability to compromise CDNJS and target thousands of sites



Print



Pro

Read More:



19 July 2021 |



A vulnerability in the CDNJS library update server, which is owned by Cloudflare and used by 12.7% of all websites on the internet, could have been abused to execute arbitrary commands and seize control of the CDNJS.


CDNJS is an open source software content delivery network and is the second most popular after Google Hosted Libraries, which itself is used by 12.8% of sites across the web. The resource hosts thousands of JavaScipt and CSS libraries that sites can adopt to embed features and tools.


The flaw, present in the update server, however, may have led to hackers executing arbitrary commands and entirely compromising the CDNJS catalogue, according to the security researcher known as Ryotak. They reported to flaw to Cloudflare on 6 April, and there’s no evidence so far that it’s been exploited in the wild.



..

Support the originator by clicking the read the rest link below.