CVE-2023-7079
Last modified
CVE-2023-7079 is a medium-severity vulnerability rated 5.7/10 on the CVSS scale. Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessible over the local network. An attacker that could trick any user on the local network into opening a malicious website could also read any file. . EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
Sending specially crafted HTTP requests and inspector messages to Wrangler's dev server could result in any file on the user's computer being accessible over the local network. An attacker that could trick any user on the local network into opening a malicious website could also read any file.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cloudflare | Wrangler | >= 3.9.0, < 3.19.0 |
References
- https://github.com/cloudflare/workers-sdk/security/advisories/GHSA-cfph-4qqh-w828Patch, Third Party Advisory
- https://github.com/cloudflare/workers-sdk/security/advisories/GHSA-cfph-4qqh-w828Patch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-7079?
How severe is CVE-2023-7079?
How do I fix CVE-2023-7079?
Are you affected by CVE-2023-7079?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
