Bug 2167571 (CVE-2022-28923)

Summary: CVE-2022-28923 caddy: an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs
Product: [Other] Security Response Reporter: Sandipan Roy <saroy>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED NOTABUG QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: amctagga, dymurray, ellin, gparvin, ibolton, jmatthew, jmontleo, joelsmith, njean, ocs-bugs, owatkins, pahickey, rgarg, rjohnson, scorneli, shbose, slucidi, sseago, stcannon, teagle, ubhargav, whayutin
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: caddy 2.5.0 Doc Type: If docs needed, set a value
Doc Text:
An open redirect flaw was found in caddy. This issue may allow a malicious user to craft a link that redirects to any url they choose.
Story Points: ---
Clone Of: Environment:
Last Closed: 2023-02-13 09:39:29 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2167572, 2167573, 2226939    
Bug Blocks: 2167589    

Description Sandipan Roy 2023-02-07 04:39:28 UTC
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

https://lednerb.de/en/publications/responsible-disclosure/caddy-open-redirect-vulnerability/

Comment 1 Sandipan Roy 2023-02-07 04:39:56 UTC
Created caddy tracking bugs for this issue:

Affects: epel-7 [bug 2167573]
Affects: fedora-all [bug 2167572]

Comment 3 Product Security DevOps Team 2023-02-13 09:39:26 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-28923