Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local servers.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: cloudflare

Published: 2023-12-29T11:53:06.669Z

Updated: 2024-08-26T20:31:04.794Z

Reserved: 2023-12-22T09:58:30.164Z

Link: CVE-2023-7078

cve-icon Vulnrichment

Updated: 2024-08-02T08:50:07.938Z

cve-icon NVD

Status : Analyzed

Published: 2023-12-29T12:15:47.537

Modified: 2024-01-05T18:12:41.400

Link: CVE-2023-7078

cve-icon Redhat

No data.