Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-28923

Опубликовано: 07 фев. 2023
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

An open redirect flaw was found in caddy. This issue may allow a malicious user to craft a link that redirects to any url they choose.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Containersrhmtc/openshift-migration-velero-plugin-for-gcp-rhel8Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-velero-restic-restore-helper-rhel8Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-velero-rhel8Not affected
OpenShift API for Data Protectionoadp/oadp-velero-plugin-for-aws-rhel9Not affected
OpenShift API for Data Protectionoadp/oadp-velero-plugin-for-gcp-rhel9Not affected
OpenShift API for Data Protectionoadp/oadp-velero-plugin-for-microsoft-azure-rhel8Not affected
OpenShift API for Data Protectionoadp/oadp-velero-restic-restore-helper-rhel8Not affected
OpenShift API for Data Protectionoadp/oadp-velero-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2acm-multicluster-globalhub-agent-containerNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2167571caddy: an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs

EPSS

Процентиль: 95%
0.16987
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 3 лет назад

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

CVSS3: 6.1
nvd
около 3 лет назад

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

CVSS3: 6.1
debian
около 3 лет назад

Caddy v2.4.6 was discovered to contain an open redirection vulnerabili ...

CVSS3: 6.1
github
около 3 лет назад

Open Redirect in Caddy

EPSS

Процентиль: 95%
0.16987
Средний

7.5 High

CVSS3