Security Advisory

CVE-2018-21246

9.8
CRITICAL

Vulnerability Description

Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
Published Date June 15, 2020
Official Source NIST NVD Advisory