CVE-2022-29718

MEDIUM6.1EPSS 0.28%

Open redirect in caddy

Published: 6/3/2022Modified: 2/4/2026
Also known as:GHSA-2927-hv3p-f3vpCGA-gq2g-9v58-7884

Description

Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References (6)