Server-Side Request Forgery (SSRF) in Miniflare
CVE-2023-7078
7.5HIGH
What is CVE-2023-7078?
A vulnerability in Miniflare allows an attacker to exploit specially crafted HTTP requests, leading to the potential delivery of arbitrary HTTP and WebSocket requests from the server. This issue is particularly concerning for configurations where Miniflare listens on external network interfaces, providing a local network attacker access to other local servers. Users running versions prior to 3.19.0 of Miniflare are especially at risk and should consider upgrading their installations to mitigate this issue.
Affected Version(s)
miniflare Windows 0
miniflare Windows 0 < 3.20231030.2