"Remote code execution in cdnjs of Cloudflare"

Tl;Dr: Path traversal on tgz archives mirrored by CDNjs.

https://blog.ryotak.me/post/cdnjs-remote-code-execution-en/ @[email protected] #bugbouty #pentest #rce #vulnerability #cloudflare #cdnjs

Remote code execution in cdnjs of Cloudflare

Preface (ζ—₯本θͺžη‰ˆγ‚‚ε…¬ι–‹γ•γ‚Œγ¦γ„γΎγ™γ€‚) Cloudflare, which runs cdnjs, is running a β€œVulnerability Disclosure Program” on HackerOne, which allows hackers to perform vulnerability assessments. This article describes vulnerabilities reported through this program and published with the permission of the Cloudflare security team. So this article is not intended to recommend you to perform an unauthorized vulnerability assessment. If you found any vulnerabilities in Cloudflare’s product, please report it to Cloudflare’s vulnerability disclosure program. TL;DR There was a vulnerability in the cdnjs library update server that could execute arbitrary