All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead to bypass of security mechanisms or confusion in handling TLS.
References
Configurations
No configuration.
History
21 Nov 2024, 08:54
Type | Values Removed | Values Added |
---|---|---|
References | () https://blog.trailofbits.com/2023/09/18/security-flaws-in-an-sso-plugin-for-caddy/ - | |
References | () https://github.com/greenpau/caddy-security/issues/270 - | |
References | () https://security.snyk.io/vuln/SNYK-GOLANG-GITHUBCOMGREENPAUCADDYSECURITY-6249863 - |
20 Feb 2024, 19:50
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
17 Feb 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-17 05:15
Updated : 2024-11-21 08:54
NVD link : CVE-2024-21499
Mitre link : CVE-2024-21499
CVE.ORG link : CVE-2024-21499
JSON object : View
Products Affected
No product.
CWE
CWE-644
Improper Neutralization of HTTP Headers for Scripting Syntax