Impact of Cloudbleed at HashiCorp
Following the public response by Cloudflare to the “Cloudbleed” incident, HashiCorp audited our use of the service to determine possible impact to our customers. HashiCorp does make use of various functionality provided by CloudFlare, including DNS resolution, but our use of the CloudFlare HTTP proxy feature is limited only to a small number of non-critical web properties. We’ve analyzed the use of those services and the data rendered during HTTP communication and are confident that they introduced minimal risk with no disclosure of personal information.
Importantly, the service atlas.hashicorp.com (aka “Terraform Enterprise”) was specifically not using the HTTP proxy feature so it remains unaffected.
We believe responsible analysis and disclosure is important to maintain trust in Internet-wide incidents like these, particularly given our DNS is resolved via the affected service provider.
Please direct any questions or concerns on this topic to support@hashicorp.com. As always, if you believe you have found a security issue in a HashiCorp web property or tool, please responsibly disclose by emailing security@hashicorp.com. Our security policy and our PGP key can be found at https://www.hashicorp.com/security
Sign up for the latest HashiCorp news
More blog posts like this one
HashiTalks 2025: 24-hours of virtual knowledge sharing
HashiTalks returns on February 20, 2025. Join our global community for 24-hours of knowledge sharing. The call for proposals is open through December 1, 2024.
5 reasons to visit HashiCorp at AfroTech ‘24
Raffles, free certifications, and recruiter conversations are just a few reasons to visit the HashiCorp booth during AfroTech.
HashiCorp at AWS re:Invent: Your blueprint to cloud success
If you’re attending AWS re:Invent in Las Vegas, Dec. 2 - Dec. 6th, visit us for breakout sessions, expert talks, and product demos to learn how to take a unified approach to Infrastructure and Security Lifecycle Management.