MEDIUM6.1
GHSA-qpm3-vr34-h8w8
Open Redirect in Caddy
Quick fix
GHSA-qpm3-vr34-h8w8 — github.com/caddyserver/caddy/v2: upgrade to the fixed version with the command below.
go get github.com/caddyserver/caddy/v2@v2.5.0-beta.1Details
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/caddyserver/caddy/v2
Introduced in:
0Fixed in: 2.5.0-beta.1Fix
go get github.com/caddyserver/caddy/v2@v2.5.0-beta.1References
- https://nvd.nist.gov/vuln/detail/CVE-2022-28923[ADVISORY]
- https://github.com/caddyserver/caddy/commit/78b5356f2b1945a90de1ef7f2c7669d82098edbd[WEB]
- https://github.com/caddyserver/caddy[PACKAGE]
- https://lednerb.de/en/publications/responsible-disclosure/caddy-open-redirect-vulnerability[WEB]
- https://pkg.go.dev/vuln/GO-2023-1567[WEB]