PT-2023-32863 · Miniflare · Miniflare
Lekensteyn
·
Published
2023-12-29
·
Updated
2024-01-05
·
CVE-2023-7078
CVSS v3.1
8.1
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Miniflare versions prior to 3.20231030.2
Description
Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces, as was the default in wrangler until 3.19.0, an attacker on the local network could access other local servers.
Recommendations
For versions prior to 3.20231030.2, update to version 3.20231030.2 or later to resolve the issue.
As a temporary workaround, ensure Miniflare is configured to listen on just local interfaces by using the host: "127.0.0.1" option.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Miniflare