CVE-2022-28923

MEDIUM6.1EPSS 3.2%

Open redirect in github.com/caddyserver/caddy/v2

Published: 2/7/2023Modified: 4/30/2026

Description

Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

Affected packages (3)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (8)