Medium severity5.3NVD Advisory· Published Mar 22, 2020· Updated Jun 17, 2026
CVE-2020-10807
CVE-2020-10807
Description
auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Caldera/Calderadescription
Patches
Vulnerability mechanics
References
4- github.com/mitre/caldera/pull/1407nvdPatchThird Party Advisory
- github.com/mitre/caldera/compare/2.6.4...2.6.5nvdThird Party Advisory
- github.com/mitre/caldera/issues/1405nvdThird Party Advisory
- github.com/mitre/caldera/releases/tag/2.6.5nvdRelease NotesThird Party Advisory
News mentions
0No linked articles in our index yet.