CVE-2024-21498
- EPSS 0.16%
- Veröffentlicht 17.02.2024 05:15:10
- Zuletzt bearbeitet 23.12.2025 20:08:07
All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit ot...
CVE-2024-21499
- EPSS 0.03%
- Veröffentlicht 17.02.2024 05:15:10
- Zuletzt bearbeitet 26.02.2025 15:14:42
All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead to bypass of security mechani...
CVE-2024-21494
- EPSS 0.03%
- Veröffentlicht 17.02.2024 05:15:09
- Zuletzt bearbeitet 24.04.2025 15:15:56
All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can spoof an IP address used in the user identity module...
CVE-2024-21495
- EPSS 0.13%
- Veröffentlicht 17.02.2024 05:15:09
- Zuletzt bearbeitet 19.02.2025 15:47:31
Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vulnerable to Insecure Randomness due to using an insecure random number generation library which could possibly be predicted via a brute-force search. Attackers could use t...
CVE-2024-21497
- EPSS 0.1%
- Veröffentlicht 17.02.2024 05:15:09
- Zuletzt bearbeitet 03.03.2026 17:16:14
Versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into visiting a malicious website by crafting a convincing URL wit...
CVE-2024-21493
- EPSS 0.04%
- Veröffentlicht 17.02.2024 05:15:08
- Zuletzt bearbeitet 26.02.2025 15:14:42
All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library do not validate whether their input values are nil before...