Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-34037

Опубликовано: 22 июл. 2022
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI. Note: This has been disputed as a bug, not a security vulnerability, in the Caddy web server that emerged when an administrator's bad configuration containing a malformed request URI caused the server to return an empty reply instead of a valid HTTP response to the client.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:caddyserver:caddy:2.5.1:*:*:*:*:*:*:*

EPSS

Процентиль: 69%
0.00614
Низкий

7.5 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

redhat
больше 3 лет назад

An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI. Note: This has been disputed as a bug, not a security vulnerability, in the Caddy web server that emerged when an administrator's bad configuration containing a malformed request URI caused the server to return an empty reply instead of a valid HTTP response to the client.

suse-cvrf
больше 3 лет назад

Security update for caddy

CVSS3: 7.5
github
больше 3 лет назад

Withdrawn Advisory: Out-of-bounds Read can lead to client side denial of service

EPSS

Процентиль: 69%
0.00614
Низкий

7.5 High

CVSS3

Дефекты

CWE-125