Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://github.com/caddyserver/caddy/releases/tag/v0.10.13 | third party advisory release notes |
https://bugs.gentoo.org/715214 | third party advisory |