Github.Com Caddyserver Caddy vulnerabilities
4 known vulnerabilities affecting github.com/caddyserver_caddy.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2018-21246CRITICAL≥ 0, < 0.10.132022-10-06
CVE-2018-21246 [CRITICAL] CWE-287 Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication
Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
ghsaosv
CVE-2022-34037HIGH≥ 0, < 2.5.22022-07-23
CVE-2022-34037 [HIGH] CWE-125 Withdrawn Advisory: Out-of-bounds Read can lead to client side denial of service
Withdrawn Advisory: Out-of-bounds Read can lead to client side denial of service
## Withdrawn Advisory
This advisory has been withdrawn because it is a bug, not a vulnerability. According to the maintainer, the bug only affects the client side of the request and cannot cause a denial of service on the server.
## Original Description
An out-of-bounds read in the rewrite function at /mo
ghsaosv
CVE-2022-29718MEDIUM≥ 0, < 2.5.02022-06-03
CVE-2022-29718 [MEDIUM] CWE-601 Open redirect in caddy
Open redirect in caddy
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
ghsaosv
CVE-2018-19148LOW≥ 0, < 0.11.12022-05-14
CVE-2018-19148 [LOW] CWE-200 Caddy allows enumeration of Certificates and Hostnames
Caddy allows enumeration of Certificates and Hostnames
Caddy through 0.11.0 sends incorrect certificates for certain invalid requests, making it easier for attackers to enumerate hostnames. Specifically, when unable to match a Host header with a vhost in its configuration, it serves the X.509 certificate for a randomly selected vhost in its configuration. Repeated requests (with a nonexistent hostname in the Hos
ghsaosv