CVE-2024-21493

CVSS V2 None CVSS V3 None
Description
All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library do not validate whether their input values are nil before attempting to access elements, which can lead to a panic (index out of range). Panics during the parsing of a configuration file may introduce ambiguity and vulnerabilities, hindering the correct interpretation and configuration of the web server.
Overview
  • CVE ID
  • CVE-2024-21493
  • Assigner
  • snyk
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-17T05:00:08.927Z
  • Last Modified Date
  • 2024-03-06T14:09:47.512Z
History
Created Old Value New Value Data Type Notes
2024-06-26 15:24:18 Added to TrackCVE