CVE-2023-7078

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-7078
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-7078.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-7078
Aliases
Related
Published
2023-12-29T12:15:47Z
Modified
2025-01-08T09:41:58.115866Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local servers.

References

Affected packages

Git / github.com/cloudflare/workers-sdk

Affected ranges

Type
GIT
Repo
https://github.com/cloudflare/workers-sdk
Events

Affected versions

@cloudflare/pages-shared@0.*

@cloudflare/pages-shared@0.11.0
@cloudflare/pages-shared@0.11.1

create-cloudflare@2.*

create-cloudflare@2.7.0
create-cloudflare@2.7.1

miniflare@3.*

miniflare@3.20230821.0
miniflare@3.20230904.0
miniflare@3.20230918.0
miniflare@3.20230922.0
miniflare@3.20231002.0
miniflare@3.20231002.1
miniflare@3.20231010.0
miniflare@3.20231016.0
miniflare@3.20231023.0
miniflare@3.20231025.0
miniflare@3.20231030.0
miniflare@3.20231030.1

wrangler@3.*

wrangler@3.16.0
wrangler@3.17.0
wrangler@3.17.1