CVE-2018-21246: Critical severity caddyserver Caddy vulnerability
Published Jun 15, 2020
·Updated
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
Affected Software
1 affected component
caddyserver Caddy<0.10.3
Event History
Jun 15, 2020
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
Description
Frequently Asked Questions
1
What is CVE-2018-21246?
CVE-2018-21246 is a vulnerability in Caddy before version 0.10.13 that mishandles TLS client authentication, leading to an authentication bypass caused by the lack of the StrictHostMatching mode.
2
What is the severity of CVE-2018-21246?
The severity of CVE-2018-21246 is rated as critical with a score of 9.8.
3
How does CVE-2018-21246 affect Caddy?
CVE-2018-21246 affects Caddy versions up to 0.10.3, allowing an authentication bypass due to mishandling of TLS client authentication.
4
Is there a fix available for CVE-2018-21246?
Yes, the fix for CVE-2018-21246 is included in Caddy version 0.10.13 or later.
5
Where can I find more information about CVE-2018-21246?
You can find more information about CVE-2018-21246 on the following references: [1] and [2].