Security Advisory

CVE-2016-6287

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-01-10 15:00:00
Last updated 2024-08-06 01:22:20
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The "http-client" egg always used a HTTP_PROXY environment variable to determine whether HTTP traffic should be routed via a proxy, even when running as a CGI process. Under several web servers this would mean a user-supplied "Proxy" header could allow an attacker to direct all HTTP requests through a proxy (also known as a "httpoxy" attack). This affects all versions of http-client before 0.10.