Arbitrary remote code execution within wrangler dev Workers sandbox
CVE-2023-7080

8.5HIGH

Key Information:

Vendor

Cloudflare

Status
Vendor
CVE Published:
29 December 2023

What is CVE-2023-7080?

The Cloudflare Workers V8 Inspector allows arbitrary code execution within the Workers sandbox when used for debugging. An improperly configured inspector server can be accessed by attackers on the local network, who can exploit this by tricking users into opening a malicious site. This vulnerability occurs due to a lack of Origin/Host header validation and has been addressed in wrangler versions 3.19.0 and 2.20.2. Prior versions allow attackers to potentially access production resources if remote development commands are used.

Affected Version(s)

wrangler Windows 0 <= 3.0.0

wrangler Windows 0 < 3.19.0

wrangler Windows 0 <= 2.0.0

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Peter Wu (Lekensteyn)
.