Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:25685
HistoryJun 16, 2020 - 2:15 a.m.

Authentication Bypass

2020-06-1602:15:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
7

EPSS

0.003

Percentile

71.0%

github.com/caddyserver/caddy is vulnerable to authentication bypass. When TLS is used for client authentication, it does not enforce a tls: StrictHostMatching mode for client authentication, leading to a bypass of TLS authentication.

EPSS

0.003

Percentile

71.0%