CVE-2022-28923: Medium severity caddyserver Caddy vulnerability
Published Feb 6, 2023
·Updated
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs
Affected Software
2 affected componentsFixes available
go/github.com/caddyserver/caddy/v2<2.5.0-beta.1
2.5.0-beta.1
caddyserver Caddy=2.4.6
Remediation
Event History
Feb 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 7, 2023
Advisory Published
via GitHub·12:30 AM
Frequently Asked Questions
1
What is CVE-2022-28923?
CVE-2022-28923 is an open redirection vulnerability in Caddy v2.4.6.
2
How does CVE-2022-28923 affect Caddy?
CVE-2022-28923 allows attackers to redirect users to phishing websites via crafted URLs in Caddy v2.4.6.
3
What is the severity of CVE-2022-28923?
CVE-2022-28923 has a severity rating of medium (6.1).
4
How can I fix CVE-2022-28923?
To fix CVE-2022-28923, update Caddy to a version higher than 2.4.6.
5
Where can I find more information about CVE-2022-28923?
More information about CVE-2022-28923 can be found at https://lednerb.de/en/publications/responsible-disclosure/caddy-open-redirect-vulnerability/.