PT-2020-8890 · Caddy · Caddy
Sam James
·
Published
2020-06-15
·
Updated
2022-10-06
·
CVE-2018-21246
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Caddy versions prior to 0.10.13
Description
The issue is related to the mishandling of TLS client authentication. This is caused by the lack of the StrictHostMatching mode, allowing an attacker to bypass TLS client authentication. An attacker may indicate an SNI during the TLS handshake that is different from the name in the HTTP Host header, which can lead to an authentication bypass.
Recommendations
For versions prior to 0.10.13, update to version 0.10.13 or later to resolve the issue. As a temporary workaround, consider enabling the StrictHostMatching mode to minimize the risk of exploitation.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Caddy