Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-93x8-66j2-wwr5

Опубликовано: 17 фев. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

Server-Side Request Forgery in github.com/greenpau/caddy-security

All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit other vulnerabilities within the network by exploiting this vulnerability.

Пакеты

Наименование

github.com/greenpau/caddy-security

go
Затронутые версииВерсия исправления

<= 1.1.23

Отсутствует

EPSS

Процентиль: 37%
0.00156
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 5.3
nvd
почти 2 года назад

All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit other vulnerabilities within the network by exploiting this vulnerability.

EPSS

Процентиль: 37%
0.00156
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-918