Description
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
Remediation
References
Related Vulnerabilities
OpenSSL Numeric Errors Vulnerability (CVE-2016-2105)
Check for apache versions up to 1.3.25, 2.0.38
WordPress Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2012-5868)
WordPress 3.7.x Multiple Vulnerabilities (3.7 - 3.7.31)
Oracle Database Server CVE-2009-0997 Vulnerability (CVE-2009-0997)