GO-2020-0043
Dashboard / Vulnerabilities / GO-2020-0043
GO-2020-0043
Published: 14 Apr 2021Last Modified: 20 May 2024
Aliases:
Summary: Authentication bypass in github.com/mholt/caddy
Details: Due to improper TLS verification when serving traffic for multiple SNIs, an attacker may bypass TLS client authentication by indicating an SNI during the TLS handshake that is different from the name in the HTTP Host header.
References: https://github.com/caddyserver/caddy/pull/2099, https://github.com/caddyserver/caddy/commit/4d9ee000c8d2cbcdd8284007c1e0f2da7bc3c7c3, https://bugs.gentoo.org/715214
Affected packages
Package
Name: github.com/mholt/caddy
Purl: pkg:golang/github.com/mholt/caddy
Affected ranges
Type: SEMVER
Events:
Introduced- 0
Fixed -0.10.13
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
