Lack of data validation In github.com/greenpau/caddy-security
Description
Improper Neutralization of HTTP Headers in github.com/greenpau/caddy-security All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead to bypass of security mechanisms or confusion in handling TLS.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
go | 1.1.24 |
Aliases
1. 2. 3. 4.
References
1. 2.