Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-gr7w-x2jp-3xgw: Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication

Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.

ghsa
#git#auth#ssl

Caddy vulnerable to Authentication Bypass due to mishandling of TLS client authentication

Critical severity GitHub Reviewed Published Oct 6, 2022 • Updated Oct 6, 2022

ghsa: Latest News

GHSA-cwwm-hr97-qfxm: SpiceDB checks involving relations with caveats can result in no permission when permission is expected