Vulnerability Details CVE-2022-29718
Caddy v2.4 was discovered to contain an open redirect vulnerability. A remote unauthenticated attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.6%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 5.8
Products affected by CVE-2022-29718
-
cpe:2.3:a:caddyserver:caddy:2.4.0
-
cpe:2.3:a:caddyserver:caddy:2.4.1
-
cpe:2.3:a:caddyserver:caddy:2.4.2
-
cpe:2.3:a:caddyserver:caddy:2.4.3
-
cpe:2.3:a:caddyserver:caddy:2.4.4
-
cpe:2.3:a:caddyserver:caddy:2.4.5
-
cpe:2.3:a:caddyserver:caddy:2.4.6