PT-2020-8890 · Caddy · Caddy

Sam James

·

Published

2020-06-15

·

Updated

2022-10-06

·

CVE-2018-21246

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Caddy versions prior to 0.10.13
Description The issue is related to the mishandling of TLS client authentication. This is caused by the lack of the StrictHostMatching mode, allowing an attacker to bypass TLS client authentication. An attacker may indicate an SNI during the TLS handshake that is different from the name in the HTTP Host header, which can lead to an authentication bypass.
Recommendations For versions prior to 0.10.13, update to version 0.10.13 or later to resolve the issue. As a temporary workaround, consider enabling the StrictHostMatching mode to minimize the risk of exploitation.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2018-21246
GHSA-GR7W-X2JP-3XGW
GO-2020-0043

Affected Products

Caddy