Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-2927-hv3p-f3vp: Open redirect in caddy

Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.

ghsa
#vulnerability#web#git#auth

Package

gomod github.com/caddyserver/caddy (Go )

Affected versions

< 2.5.0

Package

gomod github.com/caddyserver/caddy/v2 (Go )

Affected versions

< 2.5.0

Related news

CVE-2022-29718: caddyhttp: Fix `MatchPath` sanitizing by francislavoie · Pull Request #4499 · caddyserver/caddy

Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.