CVE-2024-21499

CVSS V2 None CVSS V3 None
Description
All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead to bypass of security mechanisms or confusion in handling TLS.
Overview
  • CVE ID
  • CVE-2024-21499
  • Assigner
  • snyk
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-02-17T05:00:06.256Z
  • Last Modified Date
  • 2024-03-06T14:09:47.106Z
History
Created Old Value New Value Data Type Notes
2024-06-26 15:17:03 Added to TrackCVE