PT-2023-32864 · Wrangler · Wrangler
Lekensteyn
·
Publicado
2023-12-29
·
Atualizado
2024-01-05
·
CVE-2023-7079
CVSS v3.1
6.9
Média
| Vetor | AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Wrangler versions prior to 3.19.0
Description
Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessible over the local network. An attacker that could trick any user on the local network into opening a malicious website could also read any file.
Recommendations
For versions prior to 3.19.0, update to version 3.19.0 or later.
As a temporary workaround, configure Wrangler to listen on local interfaces instead with
wrangler dev --ip 127.0.0.1. This removes the local network as an attack vector, but does not prevent an attack from visiting a malicious website.Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wrangler