[Bug 1200279] New: VUL-0: CVE-2022-29718: caddy: unauthenticated open redirect vulnerability
http://bugzilla.opensuse.org/show_bug.cgi?id=1200279 Bug ID: 1200279 Summary: VUL-0: CVE-2022-29718: caddy: unauthenticated open redirect vulnerability Classification: openSUSE Product: openSUSE Distribution Version: Leap 15.4 Hardware: Other URL: https://smash.suse.de/issue/333631/ OS: Other Status: NEW Severity: Minor Priority: P5 - None Component: Security Assignee: alexandre.vicenzi@suse.com Reporter: thomas.leroy@suse.com QA Contact: security-team@suse.de Found By: Security Response Team Blocker: --- CVE-2022-29718 Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links. Upstream fix: https://github.com/caddyserver/caddy/commit/3fe2c73dd04f7769a9d9673236cb94b7... References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-29718 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29718 https://github.com/caddyserver/caddy/pull/4499 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1200279 http://bugzilla.opensuse.org/show_bug.cgi?id=1200279#c1 --- Comment #1 from Thomas Leroy <thomas.leroy@suse.com> --- openSUSE:Backports:SLE-15-SP4 should be affected -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1200279 http://bugzilla.opensuse.org/show_bug.cgi?id=1200279#c2 --- Comment #2 from Alexandre Vicenzi <alexandre.vicenzi@suse.com> --- Update request sent: https://build.opensuse.org/request/show/981148 -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1200279 http://bugzilla.opensuse.org/show_bug.cgi?id=1200279#c3 --- Comment #3 from OBSbugzilla Bot <bwiedemann+obsbugzillabot@suse.com> --- This is an autogenerated message for OBS integration: This bug (1200279) was mentioned in https://build.opensuse.org/request/show/981174 Backports:SLE-15-SP4 / caddy -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com