Vulnerability Report: GO-2023-1567
- CVE-2022-28923, GHSA-qpm3-vr34-h8w8
- Affects: github.com/caddyserver/caddy/v2
- Published: Feb 16, 2023
- Modified: May 20, 2024
Due to improper request sanitization, a crafted URL can cause the static file handler to redirect to an attacker chosen URL, allowing for open redirect attacks.
For detailed information about this vulnerability, visit https://github.com/advisories/GHSA-qpm3-vr34-h8w8.
Affected Packages
-
PathGo VersionsSymbols
-
before v2.5.0-beta.1
-
before v2.5.0-beta.1
Aliases
References
- https://lednerb.de/en/publications/responsible-disclosure/caddy-open-redirect-vulnerability/
- https://github.com/caddyserver/caddy/commit/78b5356f2b1945a90de1ef7f2c7669d82098edbd
- https://github.com/advisories/GHSA-qpm3-vr34-h8w8
- https://vuln.go.dev/ID/GO-2023-1567.json
Credits
- Mayank Mukhi (@Hunt2behunter)
Feedback
See anything missing or incorrect?
Suggest an edit to this report.