S4E just found a medium-severity finding from [ai] private ip disclosure detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Dec 16, 2023

Cloudflare External Image Resizing Misconfiguration Scanner

There is a server side request forgery (SSRF) vulnerability in Cloudflare.

Est. Time~5 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
19
Vulnerabilities Found
confirmed findings
References
Detail

Cloudflare Image Resizing defaults to restricting resizing to the same domain. This prevents third parties from resizing any image at any origin. However, you can enable this option if you check Resize images from any origin.

Solution Advice
  • You need to apply related fixes.
  • Sanitize all parameters received as input from the user.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Online Cloudflare External Image Resizing Misconfiguration Scanner | S4E