Greenpau develops a focused security module for the Caddy web server, where its vulnerabilities center on authentication and output-handling issues including authentication bypass by spoofing, improper encoding and escaping, cross-site scripting, and input validation weaknesses. These patterns are characteristic of web-layer security components and reflect the complexity of credential handling and content-sanitization logic in middleware. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Greenpau over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-21495CRITICAL Versions of the package github.com/greenpau/caddy-security before 1.0.42 are vulnerable to Insecure Randomness due to using an insecure random number generation library which could | Feb 17, 2024 | 9.8 | 26 | NO | NO |
CVE-2024-21497MEDIUM Versions of the package github.com/greenpau/caddy-security are vulnerable to Open Redirect via the redirect_url parameter. An attacker could perform a phishing attack and trick us | Feb 17, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-21494MEDIUM All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization | Feb 17, 2024 | 5.4 | 17 | NO | NO |
CVE-2024-21493MEDIUM All versions of the package github.com/greenpau/caddy-security are vulnerable to Improper Validation of Array Index when parsing a Caddyfile. Multiple parsing functions in the affe | Feb 17, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-21499MEDIUM All versions of the package github.com/greenpau/caddy-security are vulnerable to HTTP Header Injection via the X-Forwarded-Proto header due to redirecting to the injected protocol. | Feb 17, 2024 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Greenpau.
Media articles that mention a CVE ID that affects a product developed by Greenpau — matched by CVE ID, not by vendor name.