Required CVE Record Information
Description
The "http-client" egg always used a HTTP_PROXY environment variable to determine whether HTTP traffic should be routed via a proxy, even when running as a CGI process. Under several web servers this would mean a user-supplied "Proxy" header could allow an attacker to direct all HTTP requests through a proxy (also known as a "httpoxy" attack). This affects all versions of http-client before 0.10.
References 2 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- lists.gnu.org: [chicken-announce] 20160721 [SECURITY] spiffy-cgi-handlers and http-client updated to prevent "httpoxy" attack mailing-listx_transferred
- securityfocus.com: 92105 vdb-entryx_transferred