HTTP Header Injection Vulnerability in Caddy Security
CVE-2024-21499
4.3MEDIUM
Key Information:
- Vendor
- CVE Published:
- 17 February 2024
What is CVE-2024-21499?
All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol.Exploiting this vulnerability could lead to bypass of security mechanisms or confusion in handling TLS.
Affected Version(s)
github.com/greenpau/caddy-security 0