Description
Caddy before 0.10.13 mishandles TLS client authentication, as demonstrated by an authentication bypass caused by the lack of the StrictHostMatching mode.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2021-2157 Vulnerability (CVE-2021-2157)
WordPress 4.8.x Multiple Vulnerabilities (4.8 - 4.8.20)
WordPress Plugin Twitter Feed:Embedded Timeline 'url' Parameter Cross-Site Scripting (0.3.1)
WordPress Plugin Admin Columns Cross-Site Scripting (4.3.1)
WordPress Plugin BulletProof Security Cross-Site Scripting (.47)