Withdrawn Advisory: Out-of-bounds Read can lead to client side denial of service
High severity
GitHub Reviewed
Published
Jul 23, 2022
to the GitHub Advisory Database
•
Updated May 6, 2024
Withdrawn
This advisory was withdrawn on May 6, 2024
Description
Published by the National Vulnerability Database
Jul 22, 2022
Published to the GitHub Advisory Database
Jul 23, 2022
Reviewed
Jul 27, 2022
Withdrawn
May 6, 2024
Last updated
May 6, 2024
Withdrawn Advisory
This advisory has been withdrawn because it is a bug, not a vulnerability. According to the maintainer, the bug only affects the client side of the request and cannot cause a denial of service on the server.
Original Description
An out-of-bounds read in the rewrite function at /modules/caddyhttp/rewrite/rewrite.go in Caddy v2.5.1 allows attackers to cause a Denial of Service (DoS) on the client side via a crafted URI.
References