Vulnerabilities > Caddyserver > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-06-15 CVE-2018-21246 Improper Authentication vulnerability in Caddyserver Caddy
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
network
low complexity
caddyserver CWE-287
critical
9.8