Cloudflare Fixes ACME Validation Bug Allowing WAF Bypass to Origin Servers
A security flaw in Cloudflare's Automatic Certificate Management Environment (ACME) validation logic that allowed access to origin servers and circumvention of security measures has been fixed.According to Hrushikesh Deshpande, Andrew Mitchell, and Leland Garofalo of the web infrastructure company, the vulnerability stemmed from the way our edge network handled requests intended for the ACME HTTP-01 challenge path (.well-known/acme-challenge/*).
According to the web infrastructure business, there is no proof that the vulnerability has ever been used maliciously.
A communications protocol called ACME (RFC 8555) makes it easier for SSL/TLS certificates to be automatically issued, renewed, and revoked. Challenges are used to verify domain ownership for each certificate that a certifica...

