Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fwvg-2739-22v7

Опубликовано: 29 дек. 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Miniflare vulnerable to Server-Side Request Forgery (SSRF)

Impact

Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local servers.

Patches

The issue was fixed in miniflare@3.20231030.2.

Workarounds

Ensure Miniflare is configured to listen on just local interfaces. This is the default behaviour, but can also be configured with the host: "127.0.0.1" option.

References

Пакеты

Наименование

miniflare

npm
Затронутые версииВерсия исправления

>= 3.20230821.0, < 3.20231030.2

3.20231030.2

EPSS

Процентиль: 17%
0.00053
Низкий

7.5 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local servers.

EPSS

Процентиль: 17%
0.00053
Низкий

7.5 High

CVSS3

Дефекты

CWE-918