Caddy 是一个可扩展的服务器平台,默认使用 TLS。在 2.11.3 及更早版本中,三个与配置相关的弱点影响了处理程序和占位符层。在 中,当重写 URI 以字面问号结尾时, 会将攻击者控制的替换字节传递到 进行第二次占位符扩展,从而允许注入的环境变量或请求变量占位符泄露数据;当注册了文件提供程序时,注入的文件占位符还可泄露可读文件内容。该问题已在 2.11.4 版本中修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| caddyserver | caddy | < 2.11.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet