ZeroHour

CVE-2018-21246

CVSS 3.1
9.8 critical
EPSS
3%p85
Published
()
Modified
Description

Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.

Vendors
caddyserver
Products
caddy
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.