CVE-2022-28923 – github.com/caddyserver/caddy/v2
Package
Manager: go
Name: github.com/caddyserver/caddy/v2
Vulnerable Version: >=0 <2.5.0-beta.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
EPSS: 0.13247 pctl0.939
Details
Open Redirect in Caddy Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs
Metadata
Created: 2023-02-07T00:30:24Z
Modified: 2025-03-27T03:53:05Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-qpm3-vr34-h8w8/GHSA-qpm3-vr34-h8w8.json
CWE IDs: ["CWE-601"]
Alternative ID: GHSA-qpm3-vr34-h8w8
Finding: F156
Auto approve: 1