Skip to content
CloudflareGHSA-fwvg-2739-22v7

Server-Side Request Forgery (SSRF) in Miniflare

High8.0CVE-2023-7078 · Published Dec 29, 2023

### Impact Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in `wrangler` until `3.19.0`), an attacker on the local network could access other local servers. ### Patches The issue was fixed in `miniflare@3.20231030.2`. ### Workarounds Ensure Miniflare is configured to listen on just local interfaces. This is the default behaviour, but can also be configured with the `host: "127.0.0.1"` option. ### References - https://github.com/cloudflare/workers-sdk/pull/4532

GitHub advisory

Affected versions

PackageAffectedFixed in
miniflare
npm
>= 3.20230821.0, < 3.20231030.23.20231030.2
Details and references
CVSS 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-918

More Cloudflare advisories

All Cloudflare
Advisory
Information disclosure of Cloudflare API for low privileged users
High8.1Jan 29, 2024
Kyber: timing side-channel (kyberslash2)
HighJan 8, 2024
Arbitrary remote code execution within `wrangler dev` Workers sandbox
High8.5Dec 29, 2023
Arbitrary remote file read in Wrangler dev server
Medium6.9Dec 29, 2023
Unbounded queuing of path validation messages in cloudflare-quiche
Medium5.3Dec 12, 2023
Resource exhaustion via memory leak in tokio-boring
Medium5.3Dec 5, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.