Description
All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library do not validate whether their input values are nil before attempting to access elements, which can lead to a panic (index out of range). Panics during the parsing of a configuration file may introduce ambiguity and vulnerabilities, hindering the correct interpretation and configuration of the web server.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0575 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library do not validate whether their input values are nil before attempting to access elements, which can lead to a panic (index out of range). Panics during the parsing of a configuration file may introduce ambiguity and vulnerabilities, hindering the correct interpretation and configuration of the web server. |
Github GHSA |
GHSA-8h95-jcp5-pjpr | Improper Validation of Array Index in github.com/greenpau/caddy-security |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2024-08-01T22:20:40.991Z
Reserved: 2023-12-22T12:33:20.118Z
Link: CVE-2024-21493
Updated: 2024-08-01T22:20:40.991Z
Status : Awaiting Analysis
Published: 2024-02-17T05:15:08.747
Modified: 2024-11-21T08:54:32.820
Link: CVE-2024-21493
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA