An issue was found in caddy, in versions before 0.10.13, tls: StrictHostMatching mode is not enabled which could result in client auth bypass.
Created caddy tracking bugs for this issue: Affects: epel-7 [bug 1831721] Affects: fedora-all [bug 1831719]
Upstream Changelog: https://github.com/caddyserver/caddy/releases/tag/v0.10.13
This hasn't been an issue in Fedora or EPEL packages in 2 years. See the respective tracking bugs for more details.
References: https://bugs.gentoo.org/715214
Upsteam ticket: https://github.com/caddyserver/caddy/issues/2095
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-21246