CVE-2023-3348
Last modified
CVE-2023-3348 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. The Wrangler command line tool (<=wrangler@3.1.0 or <=wrangler@2.20.1) was affected by a directory traversal vulnerability when running a local development server for Pages (wrangler pages dev command). This vulnerability enabled an attacker in the same network as the victim to connect to the local development server and access the victim's files present outside of the directory for the development server. . EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
The Wrangler command line tool (<=wrangler@3.1.0 or <=wrangler@2.20.1) was affected by a directory traversal vulnerability when running a local development server for Pages (wrangler pages dev command). This vulnerability enabled an attacker in the same network as the victim to connect to the local development server and access the victim's files present outside of the directory for the development server.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cloudflare | Wrangler | < 3.1.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3348?
How severe is CVE-2023-3348?
How do I fix CVE-2023-3348?
Are you affected by CVE-2023-3348?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
