QID 997391

Date Published: 2024-02-22

QID 997391: GO (Go) Security Update for github.com/greenpau/caddy-security (GHSA-93x8-66j2-wwr5)

All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit other vulnerabilities within the network by exploiting this vulnerability.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.3 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Github security advisory GHSA-93x8-66j2-wwr5 for updates and patch information.
    Vendor References

    CVEs related to QID 997391

    Software Advisories
    Advisory ID Software Component Link