QID 996473

Date Published: 2024-01-04

QID 996473: NodeJs (Npm) Security Update for miniflare (GHSA-fwvg-2739-22v7)

Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local servers.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.1 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-fwvg-2739-22v7 for updates and patch information.
    Vendor References

    CVEs related to QID 996473

    Software Advisories
    Advisory ID Software Component Link
    GHSA-fwvg-2739-22v7 miniflare URL Logo github.com/advisories/GHSA-fwvg-2739-22v7