CVE-2023-7078 HIGH

CVE-2023-7078: Server-Side Request Forgery (SSRF) in Miniflare

Vendor Cloudflare
Product miniflare
Weakness CWE-918 · SSRF
Published December 29, 2023
Last update August 26, 2024

CVSS base score

7.5/10
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N

What the vulnerability does

01Description

Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local servers.

Key dates

02Disclosure timeline

December 29, 2023 CVE published
August 26, 2024 Record updated