Description
All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can spoof an IP address used in the user identity module (/whoami API endpoint). This could lead to unauthorized access if the system trusts this spoofed IP address.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0735 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can spoof an IP address used in the user identity module (/whoami API endpoint). This could lead to unauthorized access if the system trusts this spoofed IP address. |
Github GHSA |
GHSA-vj36-3ccr-6563 | Authentication Bypass by Spoofing in github.com/greenpau/caddy-security |
References
History
Thu, 24 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Greenpau
Greenpau caddy-security |
|
| CPEs | cpe:2.3:a:greenpau:caddy-security:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Greenpau
Greenpau caddy-security |
Thu, 24 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Github.com\/greenpau\/caddy-security
Github.com\/greenpau\/caddy-security github.com\/greenpau\/caddy-security |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:github.com\/greenpau\/caddy-security:github.com\/greenpau\/caddy-security:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Github.com\/greenpau\/caddy-security
Github.com\/greenpau\/caddy-security github.com\/greenpau\/caddy-security |
|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2025-04-24T15:12:20.920Z
Reserved: 2023-12-22T12:33:20.118Z
Link: CVE-2024-21494
Updated: 2024-08-01T22:20:40.577Z
Status : Modified
Published: 2024-02-17T05:15:09.077
Modified: 2025-04-24T15:15:56.593
Link: CVE-2024-21494
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA