CVE-2024-21498

MEDIUM

caddy-security - Server-Side Request Forgery via X-Forwarded-Host Header Manipulation

Title source: llm
STIX 2.1

Description

All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit other vulnerabilities within the network by exploiting this vulnerability.

Scores

CVSS v3 5.3
EPSS 0.0055
EPSS Percentile 42.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
authcrunch/caddy-security
greenpau/caddy-security 0Go
Published Feb 17, 2024
Tracked Since Feb 18, 2026