Description

The Caddy web server is an open-source load balancer, reverse proxy, web server written in Go.

Caddy is dynamically configurable with a RESTful JSON API. Acunetix determined that it was possible to access this REST interface without authentication.

Remediation

Restrict access to the Caddy API interface.

Related Vulnerabilities