CVE-2023-7078: Server-Side Request Forgery (SSRF) in Miniflare
Impact Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local servers.
Patches The issue was fixed in miniflare@3.20231030.2.
Workarounds Ensure Miniflare is configured to listen on just local interfaces. This is the default behaviour, but can also be configured with the host: "127.0.0.1" option.
References - https://github.com/cloudflare/workers-sdk/pull/4532
Other sources
Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local servers.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7078?
CVE-2023-7078 has a high severity due to the potential for arbitrary HTTP and WebSocket requests from the server.
How do I fix CVE-2023-7078?
To fix CVE-2023-7078, update Miniflare to version 3.20231030.2 or later.
What versions of Miniflare are affected by CVE-2023-7078?
CVE-2023-7078 affects Miniflare versions between 3.20230821.0 and 3.20231030.2.
Can CVE-2023-7078 be exploited remotely?
Yes, CVE-2023-7078 can be exploited remotely if Miniflare is configured to listen on external network interfaces.
What impact does CVE-2023-7078 have on my application?
The impact of CVE-2023-7078 includes the risk of unauthorized HTTP and WebSocket requests that could compromise application security.