CVE-2022-29718: Medium severity caddyserver Caddy vulnerability
Published Jun 2, 2022
·Updated
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
Affected Software
1 affected component
caddyserver Caddy>=2.4.0<2.5.0
Remediation
Patch Available
Event History
Jun 2, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-29718?
CVE-2022-29718 is an open redirect vulnerability in Caddy v2.4.
2
How does CVE-2022-29718 work?
CVE-2022-29718 allows a remote unauthenticated attacker to redirect users to arbitrary web URLs by tricking them into clicking on crafted links.
3
Which version of Caddy is affected by CVE-2022-29718?
Versions between 2.4.0 and 2.5.0 of Caddy are affected by CVE-2022-29718.
4
What is the severity of CVE-2022-29718?
CVE-2022-29718 has a severity rating of medium with a CVSS score of 6.1.
5
How can CVE-2022-29718 be fixed?
To fix CVE-2022-29718, users should update Caddy to a version higher than 2.5.0.