VDB
Sign up
MEDIUM6.1

GHSA-2927-hv3p-f3vp

Open redirect in caddy

Quick fix

GHSA-2927-hv3p-f3vp — github.com/caddyserver/caddy: upgrade to the fixed version with the command below.

go get github.com/caddyserver/caddy@v2.5.0

Details

Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/caddyserver/caddy
Introduced in: 0Fixed in: 2.5.0
Fixgo get github.com/caddyserver/caddy@v2.5.0
Go/github.com/caddyserver/caddy/v2
Introduced in: 0Fixed in: 2.5.0
Fixgo get github.com/caddyserver/caddy/v2@v2.5.0

References