CVE-2020-10807: Mitre Caldera
Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.
auth_svc in Caldera before 2.6.5 allows authentication bypass (for REST API requests) via a forged "localhost" string in the HTTP Host header.
Affected products
- Mitre Caldera: before 2.6.5 (fixed in 2.6.5)
Published 2020-03-22. Last modified 2026-06-17.