Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication
Critical severity
GitHub Reviewed
Published
Oct 6, 2022
to the GitHub Advisory Database
•
Updated Feb 14, 2023
Description
Published to the GitHub Advisory Database
Oct 6, 2022
Reviewed
Oct 6, 2022
Last updated
Feb 14, 2023
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
References