Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-1000108

Опубликовано: 10 дек. 2019
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 5.8
CVSS3: 6.1

Описание

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

2.0.3-2
cosmic

not-affected

2.0.3-2
devel

not-affected

2.0.3-2
disco

not-affected

2.0.3-2
eoan

not-affected

2.0.3-2
esm-apps/bionic

not-affected

2.0.3-2
esm-apps/focal

not-affected

2.0.3-2
esm-apps/jammy

not-affected

2.0.3-2
esm-apps/noble

not-affected

2.0.3-2

Показывать по

EPSS

Процентиль: 76%
0.00953
Низкий

5.8 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
около 6 лет назад

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS3: 6.1
debian
около 6 лет назад

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 ...

github
больше 3 лет назад

yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

EPSS

Процентиль: 76%
0.00953
Низкий

5.8 Medium

CVSS2

6.1 Medium

CVSS3