CVE-2022-28923: Open Redirect in Caddy
6.1
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.93807%
CWE
Published
2/7/2023
Updated
5/20/2024
KEV Status
No
Technology
Go
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| github.com/caddyserver/caddy/v2 | go | < 2.5.0-beta.1 | 2.5.0-beta.1 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
- The patch removes url.PathUnescape in SanitizedPathJoin, indicating improper unescaping allowed crafted paths. 2. The directoryListing URL construction changes (adding './' prefix) show previous vulnerability to colon-based scheme injection. Both functions directly relate to path handling and URL generation mechanisms described in the vulnerability reports and exploit PoC.