All versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into visiting a malicious website by crafting a convincing URL with this parameter. To exploit this vulnerability, the user must take an action, such as clicking on a portal button or using the browser’s back button, to trigger the redirection.
References
Configurations
No configuration.
History
20 Feb 2024, 19:50
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
17 Feb 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-17 05:15
Updated : 2024-02-20 19:50
NVD link : CVE-2024-21497
Mitre link : CVE-2024-21497
CVE.ORG link : CVE-2024-21497
JSON object : View
Products Affected
No product.
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')