QID 997385

Date Published: 2024-02-22

QID 997385: GO (Go) Security Update for github.com/greenpau/caddy-security (GHSA-r969-783f-6jqr)

All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead to bypass of security mechanisms or confusion in handling TLS.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-r969-783f-6jqr for updates and patch information.
    Vendor References

    CVEs related to QID 997385

    Software Advisories
    Advisory ID Software Component Link