CVE-2024-21497

MEDIUM5.4EPSS 0.10%

Open Redirect in github.com/greenpau/caddy-security

Published: 2/17/2024Modified: 3/4/2026
Also known as:GHSA-8hp3-rmr7-xh88GO-2024-2560

Description

All versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into visiting a malicious website by crafting a convincing URL with this parameter. To exploit this vulnerability, the user must take an action, such as clicking on a portal button or using the browser’s back button, to trigger the redirection.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

References (6)