Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-21499 | 1 Greenpau | 1 Caddy-security | 2025-07-12 | 4.3 Medium |
| All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead to bypass of security mechanisms or confusion in handling TLS. | ||||
| CVE-2024-21494 | 2 Github.com\/greenpau\/caddy-security, Greenpau | 2 Github.com\/greenpau\/caddy-security, Caddy-security | 2025-04-24 | 5.4 Medium |
| All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can spoof an IP address used in the user identity module (/whoami API endpoint). This could lead to unauthorized access if the system trusts this spoofed IP address. | ||||
Page 1 of 1.