Several independent reports detail a critical vulnerability, CVE-2023-50387, affecting Cloudflare's internal systems. This flaw, dubbed "Rogue Ingress," allowed unauthorized access to Cloudflare's Atlassian services, specifically Jira, Confluence, and Bitbucket. The breach was first detected on October 29, 2023, and Cloudflare confirmed the incident on January 19, 2024.
The attackers exploited a misconfigured service account credential, which had not been rotated following a prior security incident in October 2022. This credential, which was stored in a source code repository, was compromised during the earlier breach but remained active. The attackers gained persistent access to Cloudflare's systems from November 14, 2023, until they were detected and remediated.
Once inside, the threat actors created new user accounts within the Atlassian suite to maintain their access. They accessed Cloudflare's Jira bug database, Confluence wiki, and a self-hosted Bitbucket server. The Bitbucket server contained source code repositories, including those for Cloudflare's identity provider, Access, and its global network.
Cloudflare's investigation revealed that the attackers attempted to log into their corporate network using the compromised credentials but were unsuccessful due to the company's use of hardware-backed security keys, specifically FIDO2-compliant keys. This security measure prevented the attackers from gaining access to Cloudflare's production systems or customer data.
The company stated that no customer data, systems, or services were impacted by this breach. The attackers also did not gain access to Cloudflare's global network, management systems, or data centers. Cloudflare's security team contained the incident by December 15, 2023, and began a thorough forensic analysis.
The compromised credential was initially exposed during a previous incident involving Okta in October 2022. During that event, the service account credential was accessed by a third party. Cloudflare’s failure to rotate this specific credential after the 2022 incident created the vulnerability that led to the "Rogue Ingress" attack.
Cloudflare has since taken several steps to bolster its security posture. This includes rotating all production credentials, segmenting its network further, and enhancing its monitoring and alerting capabilities. The company also emphasized the importance of its hardware security key implementation in preventing a more severe breach.
The incident highlights the critical need for robust credential management and timely rotation, especially after any security event. While the attackers did not achieve their ultimate goal of accessing Cloudflare's production environment, the breach of internal development systems and source code repositories represents a significant security lapse.






