First published: Thu Jun 02 2022(Updated: )
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Caddyserver Caddy | >=2.4.0<2.5.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29718 is an open redirect vulnerability in Caddy v2.4.
CVE-2022-29718 allows a remote unauthenticated attacker to redirect users to arbitrary web URLs by tricking them into clicking on crafted links.
Versions between 2.4.0 and 2.5.0 of Caddy are affected by CVE-2022-29718.
CVE-2022-29718 has a severity rating of medium with a CVSS score of 6.1.
To fix CVE-2022-29718, users should update Caddy to a version higher than 2.5.0.