Authentication mechanism absence or evasion In github.com/mholt/caddy

Description

Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Package
Affected version
Patched versions