Description
Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local servers.
Remediation
References
https://github.com/cloudflare/workers-sdk/pull/4532
https://github.com/cloudflare/workers-sdk/security/advisories/GHSA-fwvg-2739-22v7
Related Vulnerabilities
CVE-2022-23541 Vulnerability in npm package jsonwebtoken
CVE-2021-21351 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2022-23624 Vulnerability in npm package frourio-express
CVE-2019-1010260 Vulnerability in maven package com.github.shyiko:ktlint
CVE-2019-25155 Vulnerability in maven package org.webjars.bower:dompurify