{"id":"GHSA-pmxq-pj47-j8j4","summary":"Domain restrictions bypass via DNS Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes","details":"### Impact\n\nThe proxy mode of WireMock, can be protected by the network restrictions configuration, as documented in [Preventing proxying to and recording from specific target addresses](https://wiremock.org/docs/configuration/#preventing-proxying-to-and-recording-from-specific-target-addresses). These restrictions can be configured using the domain names, and in such a case the configuration is vulnerable to the DNS rebinding attacks. A similar patch was applied in WireMock 3.0.0-beta-15 for the WireMock Webhook Extensions.\n\nThe root cause of the attack is a defect in the logic which allows for a race condition triggered by a DNS server whose address expires in between the initial validation and the outbound network request that might go to a domain that was supposed to be prohibited. Control over a DNS service is required to exploit this attack, so it has high execution complexity and limited impact.\n\n### Affected versions\n\n- WireMock 3,x until 3.0.3 (security patch), on default settings in environments with access to the network\n- WireMock 2.x until 2.35.1 (security patch), on default settings in environments with access to the network\n- Python WireMock until 2.6.1\n- WireMock Studio - all versions, this proprietary product was discontinued in 2022\n\n\n### Patches\n\n- WireMock 3.0.3 + the 3.0.3-1 Docker image\n- WireMock 2.35.1 + the 2.35.1-1 Docker image - backport to WireMock 2.x\n- Python WireMock 2.6.1\n\n### Workarounds\n\nFor WireMock:\n\n- Option 1: Configure WireMock to use IP addresses instead of the domain names in the outbound URLs subject to DNS rebinding\n- Option 2: Use external firewall rules to define the list of permitted destinations\n\nFor WireMock Studio: N/A. Switch to another distribution, there will be no fix provided. The vendor of former WireMock Studio recommends migration to [WireMock Cloud](https://www.wiremock.io/product)\n\n### References\n\n- CVE-2023-41327 - Related issue in the WireMock Webhooks Extension\n","aliases":["BIT-wiremock-2023-41329","CVE-2023-41329","PYSEC-2026-2050"],"modified":"2026-08-24T00:35:31.834943672Z","published":"2023-09-08T12:19:49Z","database_specific":{"nvd_published_at":"2023-09-06T21:15:14Z","cwe_ids":["CWE-290","CWE-350"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-09-08T12:19:49Z"},"references":[{"type":"WEB","url":"https://github.com/wiremock/wiremock/security/advisories/GHSA-pmxq-pj47-j8j4"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-41329"},{"type":"PACKAGE","url":"https://github.com/wiremock/wiremock"},{"type":"WEB","url":"https://wiremock.org/docs/configuration/#preventing-proxying-to-and-recording-from-specific-target-addresses"}],"affected":[{"package":{"name":"org.wiremock:wiremock-standalone","ecosystem":"Maven","purl":"pkg:maven/org.wiremock/wiremock-standalone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.3"}]}],"versions":["3.0.0","3.0.0-beta-11","3.0.0-beta-12","3.0.0-beta-13","3.0.0-beta-14","3.0.0-beta-15","3.0.1","3.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-pmxq-pj47-j8j4/GHSA-pmxq-pj47-j8j4.json"}},{"package":{"name":"org.wiremock:wiremock","ecosystem":"Maven","purl":"pkg:maven/org.wiremock/wiremock"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.3"}]}],"versions":["3.0.0","3.0.0-beta-11","3.0.0-beta-12","3.0.0-beta-13","3.0.0-beta-14","3.0.0-beta-15","3.0.1","3.0.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-pmxq-pj47-j8j4/GHSA-pmxq-pj47-j8j4.json"}},{"package":{"name":"com.github.tomakehurst:wiremock-jre8","ecosystem":"Maven","purl":"pkg:maven/com.github.tomakehurst/wiremock-jre8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.35.1"}]}],"versions":["2.21.0","2.22.0","2.23.0","2.23.1","2.23.2","2.24.0","2.24.1","2.25.0","2.25.1","2.26.0","2.26.1","2.26.2","2.26.3","2.27.0","2.27.1","2.27.2","2.28.0","2.28.1","2.29.0","2.29.1","2.30.0","2.30.1","2.31.0","2.32.0","2.33.0","2.33.1","2.33.2","2.34.0","2.35.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-pmxq-pj47-j8j4/GHSA-pmxq-pj47-j8j4.json"}},{"package":{"name":"com.github.tomakehurst:wiremock-jre8-standalone","ecosystem":"Maven","purl":"pkg:maven/com.github.tomakehurst/wiremock-jre8-standalone"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.35.1"}]}],"versions":["2.21.0","2.22.0","2.23.0","2.23.1","2.23.2","2.24.0","2.24.1","2.25.0","2.25.1","2.26.0","2.26.1","2.26.2","2.26.3","2.27.0","2.27.1","2.27.2","2.28.0","2.28.1","2.29.0","2.29.1","2.30.0","2.30.1","2.31.0","2.32.0","2.33.0","2.33.1","2.33.2","2.34.0","2.35.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-pmxq-pj47-j8j4/GHSA-pmxq-pj47-j8j4.json"}},{"package":{"name":"wiremock","ecosystem":"PyPI","purl":"pkg:pypi/wiremock"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.1"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.2.0","2.0.0","2.1.0","2.1.1","2.1.2","2.1.3","2.2.0","2.3.0","2.3.1","2.4.0","2.4.0a0","2.5.0","2.6.0","2.6.0a0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-pmxq-pj47-j8j4/GHSA-pmxq-pj47-j8j4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L"}]}