CVE-2023-7078
Severity CVSS v4.0:
Pending analysis
Type:
CWE-918
Server-Side Request Forgery (SSRF)
Publication date:
29/12/2023
Last modified:
05/01/2024
Description
Sending specially crafted HTTP requests to Miniflare&#39;s server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local servers.<br />
<br />
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cloudflare:miniflare:*:*:*:*:*:node.js:*:* | 3.20230821.0 (including) | 3.20231030.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



