CVE-2024-21499

MEDIUM

github.com/greenpau/caddy-security - HTTP Header Injection

Title source: llm
STIX 2.1

Description

All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead to bypass of security mechanisms or confusion in handling TLS.

Scores

CVSS v3 4.3
EPSS 0.0003
EPSS Percentile 7.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-644 CWE-116
Status published
Products (2)
greenpau/caddy-security
greenpau/caddy-security 0Go
Published Feb 17, 2024
Tracked Since Feb 18, 2026