Lucene search

K
osvGoogleOSV:GO-2020-0043
HistoryApr 14, 2021 - 8:04 p.m.

Authentication bypass in github.com/mholt/caddy

2021-04-1420:04:52
Google
osv.dev
8
github
mholt
caddy
tls
verification
authentication
bypass
http
host header
software
attacker

AI Score

9.7

Confidence

High

EPSS

0.003

Percentile

71.0%

Due to improper TLS verification when serving traffic for multiple SNIs, an attacker may bypass TLS client authentication by indicating an SNI during the TLS handshake that is different from the name in the HTTP Host header.

AI Score

9.7

Confidence

High

EPSS

0.003

Percentile

71.0%