Caddysecurity Vulnerable to Improper Validation of Array Index
CVE-2024-21493
5.3MEDIUM
Key Information:
- Vendor
- CVE Published:
- 17 February 2024
What is CVE-2024-21493?
All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library do not validate whether their input values are nil before attempting to access elements, which can lead to a panic (index out of range). Panics during the parsing of a configuration file may introduce ambiguity and vulnerabilities, hindering the correct interpretation and configuration of the web server.
Affected Version(s)
github.com/greenpau/caddy-security 0