Описание
All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit other vulnerabilities within the network by exploiting this vulnerability.
Ссылки
- Third Party AdvisoryIssue Tracking
- ExploitIssue Tracking
- Third Party Advisory
- Third Party AdvisoryIssue Tracking
- ExploitIssue Tracking
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:authcrunch:caddy-security:*:*:*:*:*:*:*:*
EPSS
Процентиль: 37%
0.00156
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-918
CWE-918
Связанные уязвимости
CVSS3: 5.3
github
почти 2 года назад
Server-Side Request Forgery in github.com/greenpau/caddy-security
EPSS
Процентиль: 37%
0.00156
Низкий
5.3 Medium
CVSS3
Дефекты
CWE-918
CWE-918