Description
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
Remediation
References
Related Vulnerabilities
SharePoint CVE-2020-0975 Vulnerability (CVE-2020-0975)
Liferay Portal Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-15839)
WordPress Plugin Protected Posts Logout Button Security Bypass (1.4.5)
WordPress Plugin Product Catalog Privilege Escalation (3.8.1)
Jboss EAP Loop with Unreachable Exit Condition ('Infinite Loop') Vulnerability (CVE-2017-2670)