클라우드플레어 워커에서 발생한 스펙터 공격으로 JWT가 유출되었다.
사이버 보안 연구자들은 클라우드플레어 워커에 대한 원격 스펙터 공격의 세부 사항을 공개했다. 이 공격은 동일한 환경에 위치한 워커에서 JSON 웹 토큰(JWT)을 초당 최대 12비트로 유출시켰으며, 이는 2021년에 시연된 이전 공격의 360배에 해당한다. 연구자들이 제어하는 공격자 워커와 피해자 워커를 사용한 엔드 투 엔드 실험이 진행되었다.
A Spectre attack leaked JWT from Cloudflare Workers at up to 12 bits/second.
Cybersecurity researchers disclosed details of a remote Spectre attack against Cloudflare Workers, leaking a JSON Web Token (JWT) from a co-located Worker at rates of up to 12 bits per second. This represents a significant increase, being 360 times the rate of an earlier attack demonstrated in 2021. The experiment utilized an attacker Worker and a victim Worker controlled by the researchers.