Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0576 | All versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into visiting a malicious website by crafting a convincing URL with this parameter. To exploit this vulnerability, the user must take an action, such as clicking on a portal button or using the browser’s back button, to trigger the redirection. |
Github GHSA |
GHSA-8hp3-rmr7-xh88 | Open Redirect in github.com/greenpau/caddy-security |
Tue, 03 Mar 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:greenpau:caddy-security:*:*:*:*:*:*:*:* |
Tue, 03 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 03 Mar 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | All versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into visiting a malicious website by crafting a convincing URL with this parameter. To exploit this vulnerability, the user must take an action, such as clicking on a portal button or using the browser’s back button, to trigger the redirection. | Versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick users into visiting a malicious website by crafting a convincing URL with this parameter. To exploit this vulnerability, the user must take an action, such as clicking on a portal button or using the browser’s back button, to trigger the redirection. |
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2026-03-03T16:28:25.943Z
Reserved: 2023-12-22T12:33:20.118Z
Link: CVE-2024-21497
Updated: 2024-08-01T22:20:40.785Z
Status : Modified
Published: 2024-02-17T05:15:09.863
Modified: 2026-03-03T17:16:14.540
Link: CVE-2024-21497
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:42:22Z
EUVD
Github GHSA