Server-Side Request Forgery (SSRF) in Miniflare
CVE-2023-7078

7.5HIGH

Key Information:

Vendor

Cloudflare

Status
Vendor
CVE Published:
29 December 2023

What is CVE-2023-7078?

A vulnerability in Miniflare allows an attacker to exploit specially crafted HTTP requests, leading to the potential delivery of arbitrary HTTP and WebSocket requests from the server. This issue is particularly concerning for configurations where Miniflare listens on external network interfaces, providing a local network attacker access to other local servers. Users running versions prior to 3.19.0 of Miniflare are especially at risk and should consider upgrading their installations to mitigate this issue.

Affected Version(s)

miniflare Windows 0

miniflare Windows 0 < 3.20231030.2

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Wu (Lekensteyn)
.