CVE-2024-21493

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/02/2024
Last modified:
26/02/2025

Description

All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affected library do not validate whether their input values are nil before attempting to access elements, which can lead to a panic (index out of range). Panics during the parsing of a configuration file may introduce ambiguity and vulnerabilities, hindering the correct interpretation and configuration of the web server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:greenpau:caddy-security:*:*:*:*:*:*:*:*