PT-2023-24355 · Wrangler · Wrangler
Mskowroncf
+1
·
Published
2023-08-03
·
Updated
2023-08-29
·
CVE-2023-3348
CVSS v3.1
5.7
Medium
| Vector | AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Wrangler versions 3.1.0 and earlier, Wrangler versions 2.20.1 and earlier
Description
The issue is related to a directory traversal vulnerability that occurs when running a local development server for Pages using the
wrangler pages dev command. This vulnerability allows an attacker on the same network as the victim to connect to the local development server and access files outside of the development server directory.Recommendations
For Wrangler versions 3.1.0 and earlier, update to a version later than 3.1.0 to resolve the issue.
For Wrangler versions 2.20.1 and earlier, update to a version later than 2.20.1 to resolve the issue.
As a temporary workaround, consider restricting access to the local development server to minimize the risk of exploitation.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wrangler