Related Vulnerabilities: CVE-2022-34037  

An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI.

Description

The MITRE CVE dictionary describes this issue as:

An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) via a crafted URI.

Additional Information

  • Bugzilla 2110269: CVE-2022-34037 caddy: oob read allows for DoS
  • CWE-125: Out-of-bounds Read
  • FAQ: Frequently asked questions about CVE-2022-34037