{"id":"openSUSE-SU-2022:10080-1","summary":"Security update for caddy","details":"This update for caddy fixes the following issues:\n\nUpdate to version 2.5.2:\n\n* admin: expect quoted ETags (#4879)\n* headers: Only replace known placeholders (#4880)\n* reverseproxy: Err 503 if all upstreams unavailable\n* reverseproxy: Adjust new TLS Caddyfile directive names (#4872)\n* fileserver: Use safe redirects in file browser\n* admin: support ETag on config endpoints (#4579)\n* caddytls: Reuse issuer between PreCheck and Issue (#4866)\n* admin: Implement /adapt endpoint (close #4465) (#4846)\n* forwardauth: Fix case when `copy_headers` is omitted (#4856)\n* Expose several Caddy HTTP Matchers to the CEL Matcher (#4715)\n* reverseproxy: Fix double headers in response handlers (#4847)\n* reverseproxy: Fix panic when TLS is not configured (#4848)\n* reverseproxy: Skip TLS for certain configured ports (#4843)\n* forwardauth: Support renaming copied headers, block support (#4783)\n* Add comment about xcaddy to main\n* headers: Support wildcards for delete ops (close #4830) (#4831)\n* reverseproxy: Dynamic ServerName for TLS upstreams (#4836)\n* reverseproxy: Make TLS renegotiation optional\n* reverseproxy: Add renegotiation param in TLS client (#4784)\n* caddyhttp: Log error from CEL evaluation (fix #4832)\n* reverseproxy: Correct the `tls_server_name` docs (#4827)\n* reverseproxy: HTTP 504 for upstream timeouts (#4824)\n* caddytls: Make peer certificate verification pluggable (#4389)\n* reverseproxy: api: Remove misleading 'healthy' value\n* Fix #4822 and fix #4779\n* reverseproxy: Add --internal-certs CLI flag #3589 (#4817)\n* ci: Fix build caching on Windows (#4811)\n* templates: Add `humanize` function (#4767)\n* core: Micro-optim in run() (#4810)\n* httpcaddyfile: Add `{err.*}` placeholder shortcut (#4798)\n* templates: Documentation consistency (#4796)\n* chore: Bump quic-go to v0.27.0 (#4782)\n* reverseproxy: Support http1.1\u003eh2c (close #4777) (#4778)\n* rewrite: Handle fragment before query (fix #4775) [boo#1201822, CVE-2022-34037]\n* httpcaddyfile: Support multiple values for `default_bind` (#4774)\n","modified":"2026-02-04T03:49:42.302811Z","published":"2022-08-06T12:01:12Z","related":["CVE-2022-34037"],"upstream":["CVE-2022-34037"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GQURFVT45F4OXOLLGP52CDBSBPTC2M4G/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201822"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-34037"}],"affected":[{"package":{"name":"caddy","ecosystem":"SUSE:Package Hub 15 SP4","purl":"pkg:rpm/suse/caddy&distro=SUSE%20Package%20Hub%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.2-bp154.2.8.1"}]}],"ecosystem_specific":{"binaries":[{"caddy":"2.5.2-bp154.2.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10080-1.json"}},{"package":{"name":"caddy","ecosystem":"openSUSE:Leap 15.4","purl":"pkg:rpm/opensuse/caddy&distro=openSUSE%20Leap%2015.4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.2-bp154.2.8.1"}]}],"ecosystem_specific":{"binaries":[{"caddy":"2.5.2-bp154.2.8.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:10080-1.json"}}],"schema_version":"1.7.3"}