Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m7gr-5w5g-36jf

Опубликовано: 23 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Withdrawn Advisory: Out-of-bounds Read can lead to client side denial of service

Withdrawn Advisory

This advisory has been withdrawn because it is a bug, not a vulnerability. According to the maintainer, the bug only affects the client side of the request and cannot cause a denial of service on the server.

Original Description

An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) on the client side via a crafted URI.

Пакеты

Наименование

github.com/caddyserver/caddy

go
Затронутые версииВерсия исправления

< 2.5.2

2.5.2

EPSS

Процентиль: 69%
0.00614
Низкий

7.5 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

redhat
больше 3 лет назад

An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI. Note: This has been disputed as a bug, not a security vulnerability, in the Caddy web server that emerged when an administrator's bad configuration containing a malformed request URI caused the server to return an empty reply instead of a valid HTTP response to the client.

CVSS3: 7.5
nvd
больше 3 лет назад

An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI. Note: This has been disputed as a bug, not a security vulnerability, in the Caddy web server that emerged when an administrator's bad configuration containing a malformed request URI caused the server to return an empty reply instead of a valid HTTP response to the client.

suse-cvrf
больше 3 лет назад

Security update for caddy

EPSS

Процентиль: 69%
0.00614
Низкий

7.5 High

CVSS3

Дефекты

CWE-125