Headline
GHSA-2927-hv3p-f3vp: Open redirect in caddy
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
Package
gomod github.com/caddyserver/caddy (Go )
Affected versions
< 2.5.0
Package
gomod github.com/caddyserver/caddy/v2 (Go )
Affected versions
< 2.5.0
Related news
CVE-2022-29718: caddyhttp: Fix `MatchPath` sanitizing by francislavoie · Pull Request #4499 · caddyserver/caddy
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.