logo

CVE-2022-28923 github.com/caddyserver/caddy/v2

Package

Manager: go
Name: github.com/caddyserver/caddy/v2
Vulnerable Version: >=0 <2.5.0-beta.1

Severity

Level: Medium

CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N

EPSS: 0.13247 pctl0.939

Details

Open Redirect in Caddy Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs

Metadata

Created: 2023-02-07T00:30:24Z
Modified: 2025-03-27T03:53:05Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-qpm3-vr34-h8w8/GHSA-qpm3-vr34-h8w8.json
CWE IDs: ["CWE-601"]
Alternative ID: GHSA-qpm3-vr34-h8w8
Finding: F156
Auto approve: 1