MEDIUM6.1
GHSA-2927-hv3p-f3vp
Open redirect in caddy
Quick fix
GHSA-2927-hv3p-f3vp — github.com/caddyserver/caddy: upgrade to the fixed version with the command below.
go get github.com/caddyserver/caddy@v2.5.0Details
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/caddyserver/caddy
Introduced in:
0Fixed in: 2.5.0Fix
go get github.com/caddyserver/caddy@v2.5.0Go/github.com/caddyserver/caddy/v2
Introduced in:
0Fixed in: 2.5.0Fix
go get github.com/caddyserver/caddy/v2@v2.5.0References
- https://nvd.nist.gov/vuln/detail/CVE-2022-29718[ADVISORY]
- https://github.com/caddyserver/caddy/pull/4499[WEB]
- https://github.com/caddyserver/caddy/pull/4499/commits/b23bdcf99cfbd09d50555a999a16468404789230[WEB]
- https://github.com/caddyserver/caddy[PACKAGE]
- https://github.com/caddyserver/caddy/releases/tag/v2.5.0[WEB]
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CP2VIUT5IKA3OKM6YWA5LTLJ2GTEIH7C[WEB]