CVE-2024-21494 - CVE House
Back to Database
Status published Medium CVE-2024-21494

All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication...

Vulnerability Description

All versions of the package github.com/greenpau/caddy-security are vulnerable to Authentication Bypass by Spoofing via the X-Forwarded-For header due to improper input sanitization. An attacker can spoof an IP address used in the user identity module (/whoami API endpoint). This could lead to unauthorized access if the system trusts this spoofed IP address.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-21494

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Maciej Domanski
  • Travis Peters
  • David Pokora

Affected Vendor

Affected Software

github.com/greenpau/caddy-security
Vulnerable Versions:
0

Timeline

Official Publish: February 17th, 2024
Last Modified: April 24th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:P

Weaknesses (CWE)