Web Hack List

Collected research

Hacking Cloudflare Pages

Audits Cloudflare Pages' Azure DevOps build pipeline and finds several routes from tenant-controlled build settings to higher-privileged stages: shell injection in repository and output paths, a world-writable metadata binary, and PATH hijacking. The flaws exposed broad GitHub and Cloudflare API credentials.

Record

Published by
slcyber.io

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of slcyber.io, first published at the original source. Preserved copies are kept so the citation survives its host.