CVE-2023-3348: Directory traversal vulnerability in Cloudflare Wrangler
Impact The Wrangler command line tool (<=wrangler@3.1.0 or <=wrangler@2.20.1) was affected by a directory traversal vulnerability when running a local development server for Pages (wrangler pages dev command). This vulnerability enabled an attacker in the same network as the victim to connect to the local development server and access the victim's files present outside of the directory for the development server.
Patches Wrangler2: Upgrade to v2.20.1 or higher. Wrangler3: Upgrade to v3.1.1 or higher.
References Workers SDK on Github Wrangler docs CVE-2023-3348
Other sources
The Wrangler command line tool (<=wrangler@3.1.0) was affected by a directory traversal vulnerability when running a local development server for Pages (wrangler pages dev command). This vulnerability enabled an attacker in the same network as the victim to connect to the local development server and access the victim's files present outside of the directory for the development server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is vulnerability CVE-2023-3348?
Vulnerability CVE-2023-3348 is a directory traversal vulnerability in the Wrangler command line tool.
How does vulnerability CVE-2023-3348 impact users?
Vulnerability CVE-2023-3348 allows an attacker in the same network as the victim to connect to local development servers and potentially access sensitive files.
Which software versions are affected by vulnerability CVE-2023-3348?
Versions wrangler@3.1.0 and wrangler@2.20.1 of the Wrangler command line tool are affected.
How severe is vulnerability CVE-2023-3348?
Vulnerability CVE-2023-3348 has a severity rating of medium with a CVSS score of 5.7.
How can users fix vulnerability CVE-2023-3348?
Users should upgrade their Wrangler command line tool to version 3.1.1 or higher to fix vulnerability CVE-2023-3348.