Description
Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local servers.
Remediation
References
https://github.com/cloudflare/workers-sdk/pull/4532
https://github.com/cloudflare/workers-sdk/security/advisories/GHSA-fwvg-2739-22v7
Related Vulnerabilities
CVE-2022-25349 Vulnerability in npm package materialize-css
CVE-2018-20677 Vulnerability in maven package org.webjars.bowergithub.angular-ui:bootstrap
CVE-2020-28458 Vulnerability in maven package org.webjars.npm:datatables.net
CVE-2023-44487 Vulnerability in maven package io.netty:netty-codec-http2
CVE-2013-7250 Vulnerability in maven package org.projectforge:projectforge-webapp