All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit other vulnerabilities within the network by exploiting this vulnerability.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-0586 All versions of the package github.com/greenpau/caddy-security are vulnerable to Server-side Request Forgery (SSRF) via X-Forwarded-Host header manipulation. An attacker can expose sensitive information, interact with internal services, or exploit other vulnerabilities within the network by exploiting this vulnerability.
Github GHSA Github GHSA GHSA-93x8-66j2-wwr5 Server-Side Request Forgery in github.com/greenpau/caddy-security
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published:

Updated: 2024-08-01T22:20:40.839Z

Reserved: 2023-12-22T12:33:20.118Z

Link: CVE-2024-21498

cve-icon Vulnrichment

Updated: 2024-08-01T22:20:40.839Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-02-17T05:15:10.087

Modified: 2024-11-21T08:54:33.530

Link: CVE-2024-21498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T16:01:41Z