Skip to main content

Improper Input Validation

CVE-2019-14243

Severity High
Score 7.5/10

Summary

github.com/mastercactapus/proxyprotocol versions prior to 0.0.2 the "headerv2.go" file , as used in the mastercactapus caddy-proxyprotocol plugin for Caddy, allows remote attackers to cause a Denial-of-Service (webserver panic and daemon crash) via a crafted HAProxy PROXY v2 request with truncated source/destination address data.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-20 - Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Advisory Timeline

  • Published