Sept. 18, 2023, noon | Trail of Bits

Security Boulevard securityboulevard.com

By Maciej Domanski, Travis Peters, and David Pokora We identified 10 security vulnerabilities within the caddy-security plugin for the Caddy web server that could enable a variety of high-severity attacks in web applications, including client-side code execution, OAuth replay attacks, and unauthorized access to resources. During our evaluation, Caddy was deployed as a reverse proxy […]


The post Security flaws in an SSO plugin for Caddy appeared first on Security Boulevard.

access applications attacks audits client client-side code code execution devops dynamic analysis enable evaluation exploits flaws go high mitigations oauth plugin program analysis replay resources security security flaws semgrep server severity sso static analysis travis unauthorized access vulnerabilities web web applications web server

Azure DevSecOps Cloud Engineer II

@ Prudent Technology | McLean, VA, USA

Security Engineer III - Python, AWS

@ JPMorgan Chase & Co. | Bengaluru, Karnataka, India

SOC Analyst (Threat Hunter)

@ NCS | Singapore, Singapore

Managed Services Information Security Manager

@ NTT DATA | Sydney, Australia

Senior Security Engineer (Remote)

@ Mattermost | United Kingdom

Penetration Tester (Part Time & Remote)

@ TestPros | United States - Remote