Bugzilla – Bug 1200279
VUL-0: CVE-2022-29718: caddy: unauthenticated open redirect vulnerability
Last modified: 2022-06-15 19:15:52 UTC
CVE-2022-29718 Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links. Upstream fix: https://github.com/caddyserver/caddy/commit/3fe2c73dd04f7769a9d9673236cb94b79ac45659 References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-29718 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-29718 https://github.com/caddyserver/caddy/pull/4499
openSUSE:Backports:SLE-15-SP4 should be affected
Update request sent: https://build.opensuse.org/request/show/981148
This is an autogenerated message for OBS integration: This bug (1200279) was mentioned in https://build.opensuse.org/request/show/981174 Backports:SLE-15-SP4 / caddy
openSUSE-SU-2022:10007-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1200279 CVE References: CVE-2022-297182 JIRA References: Sources used: openSUSE Backports SLE-15-SP4 (src): caddy-2.5.1-bp154.2.5.1