Miggo Logo

CVE-2023-7078: Miniflare vulnerable to Server-Side Request Forgery (SSRF)

7.5

CVSS Score
3.1

Basic Information

EPSS Score
0.14075%
Published
12/29/2023
Updated
12/29/2023
KEV Status
No
Technology
TechnologyJavaScript

Technical Details

CVSS Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
miniflarenpm>= 3.20230821.0, < 3.20231030.23.20231030.2

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

### Imp**t S*n*in* sp**i*lly *r**t** *TTP r*qu*sts to Mini*l*r*'s s*rv*r *oul* r*sult in *r*itr*ry *TTP *n* W**So*k*t r*qu*sts **in* s*nt *rom t** s*rv*r. I* Mini*l*r* w*s *on*i*ur** to list*n on *xt*rn*l n*twork int*r****s (*s w*s t** ****ult in `wr

Reasoning

No *n*lysis *v*il**l*