Github.Com Caddyserver Caddy vulnerabilities

4 known vulnerabilities affecting github.com/caddyserver_caddy.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1LOW1

Vulnerabilities

Page 1 of 1
CVE-2018-21246CRITICAL≥ 0, < 0.10.132022-10-06
CVE-2018-21246 [CRITICAL] CWE-287 Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
ghsaosv
CVE-2022-34037HIGH≥ 0, < 2.5.22022-07-23
CVE-2022-34037 [HIGH] CWE-125 Withdrawn Advisory: Out-of-bounds Read can lead to client side denial of service Withdrawn Advisory: Out-of-bounds Read can lead to client side denial of service ## Withdrawn Advisory This advisory has been withdrawn because it is a bug, not a vulnerability. According to the maintainer, the bug only affects the client side of the request and cannot cause a denial of service on the server. ## Original Description An out-of-bounds read in the rewrite function at /mo
ghsaosv
CVE-2022-29718MEDIUM≥ 0, < 2.5.02022-06-03
CVE-2022-29718 [MEDIUM] CWE-601 Open redirect in caddy Open redirect in caddy Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
ghsaosv
CVE-2018-19148LOW≥ 0, < 0.11.12022-05-14
CVE-2018-19148 [LOW] CWE-200 Caddy allows enumeration of Certificates and Hostnames Caddy allows enumeration of Certificates and Hostnames Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames. Specifically, when unable to match a Host header with a vhost in its configuration, it serves the X.509 certificate for a randomly selected vhost in its configuration. Repeated requests (with a nonexistent hostname in the Hos
ghsaosv