First published: Mon Feb 06 2023(Updated: )
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
go/github.com/caddyserver/caddy/v2 | <2.5.0-beta.1 | 2.5.0-beta.1 |
Caddy | =2.4.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28923 is an open redirection vulnerability in Caddy v2.4.6.
CVE-2022-28923 allows attackers to redirect users to phishing websites via crafted URLs in Caddy v2.4.6.
CVE-2022-28923 has a severity rating of medium (6.1).
To fix CVE-2022-28923, update Caddy to a version higher than 2.4.6.
More information about CVE-2022-28923 can be found at https://lednerb.de/en/publications/responsible-disclosure/caddy-open-redirect-vulnerability/.