Authentication mechanism absence or evasion In github.com/mholt/caddy
Description
Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 0.10.13 | ||
go | 0.10.13 | ||
go | v0.10.13 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3. 4. 5.