Description
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
Remediation
References
Related Vulnerabilities
Joomla! Core 1.5.x Multiple SQL Injection Vulnerabilities (1.5.0 - 1.5.21)
WordPress Plugin Brandfolder-Digital Asset Management Simplified Local/Remote File Inclusion (3.0)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-4191)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4287)