Directory traversal vulnerability in Cloudflare Wrangler
Published Aug 3, 2023
5.7
MEDIUMCVSS 3.1
EPSS 0.82%
Description
The Wrangler command line tool (<=wrangler@3.1.0 or <=wrangler@2.20.1) was affected by a directory traversal vulnerability when running a local development server for Pages (wrangler pages dev command). This vulnerability enabled an attacker in the same network as the victim to connect to the local development server and access the victim's files present outside of the directory for the development server.
Affected products
-
- Version 2StatusaffectedConstraints<2.20.1
- Version 3StatusaffectedConstraints<3.1.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Cloudflare | Wrangler | unaffected |
|
- < 3.1.1
No data.
No Red Hat product state for this CVE.
wrangler
npm
Introduced 0 Fixed 2.20.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | wrangler | 0 | 2.20.1 |
Remediation
Vendor solution
Upgrade to wrangler@3.1.1 or higher For wrangler v2 upgrade to wrangler@2.20.1 or higher
References (9)
- https://developers.cloudflare.com/workers/wrangler/ relatedProduct
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2244 Advisory
- https://github.com/advisories/GHSA-8c93-4hch-xgxp Advisory
- https://github.com/cloudflare/workers-sdk product
- https://github.com/cloudflare/workers-sdk/commit/fddffdf0c23d2ca56f2139a2c6bc278052594cba
- https://github.com/cloudflare/workers-sdk/pull/3498
- https://github.com/cloudflare/workers-sdk/releases/tag/wrangler%403.1.1
- https://github.com/cloudflare/workers-sdk/security/advisories/GHSA-8c93-4hch-xgxp vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-3348
Change history (0)
No recorded changes yet.