Bug 2167571 (CVE-2022-28923) - CVE-2022-28923 caddy: an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs
Summary: CVE-2022-28923 caddy: an open redirection vulnerability which allows attacker...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2022-28923
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2167572 2167573 2226939
Blocks: 2167589
TreeView+ depends on / blocked
 
Reported: 2023-02-07 04:39 UTC by Sandipan Roy
Modified: 2023-07-27 05:04 UTC (History)
22 users (show)

Fixed In Version: caddy 2.5.0
Doc Type: If docs needed, set a value
Doc Text:
An open redirect flaw was found in caddy. This issue may allow a malicious user to craft a link that redirects to any url they choose.
Clone Of:
Environment:
Last Closed: 2023-02-13 09:39:29 UTC
Embargoed:


Attachments (Terms of Use)

Description Sandipan Roy 2023-02-07 04:39:28 UTC
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.

https://lednerb.de/en/publications/responsible-disclosure/caddy-open-redirect-vulnerability/

Comment 1 Sandipan Roy 2023-02-07 04:39:56 UTC
Created caddy tracking bugs for this issue:

Affects: epel-7 [bug 2167573]
Affects: fedora-all [bug 2167572]

Comment 3 Product Security DevOps Team 2023-02-13 09:39:26 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2022-28923


Note You need to log in before you can comment on or make changes to this bug.