Vulnerabilities > Caddyserver > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-12-10 CVE-2023-50463 Authentication Bypass by Spoofing vulnerability in Caddyserver Caddy 0.5.0/0.5.1/0.6.0
The caddy-geo-ip (aka GeoIP) middleware through 0.6.0 for Caddy 2, when trust_header X-Forwarded-For is used, allows attackers to spoof their source IP address via an X-Forwarded-For header, which may bypass a protection mechanism (trusted_proxy directive in reverse_proxy or IP address range restrictions).
network
low complexity
caddyserver CWE-290
6.5
2023-02-06 CVE-2022-28923 Open Redirect vulnerability in Caddyserver Caddy 2.4.6
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.
network
low complexity
caddyserver CWE-601
6.1
2022-06-02 CVE-2022-29718 Open Redirect vulnerability in Caddyserver Caddy
Caddy v2.4 was discovered to contain an open redirect vulnerability.
network
low complexity
caddyserver CWE-601
6.1