VDB
Sign up
MEDIUM6.1

GHSA-qpm3-vr34-h8w8

Open Redirect in Caddy

Quick fix

GHSA-qpm3-vr34-h8w8 — github.com/caddyserver/caddy/v2: upgrade to the fixed version with the command below.

go get github.com/caddyserver/caddy/v2@v2.5.0-beta.1

Details

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/caddyserver/caddy/v2
Introduced in: 0Fixed in: 2.5.0-beta.1
Fixgo get github.com/caddyserver/caddy/v2@v2.5.0-beta.1

References