First published: Wed Mar 11 2020(Updated: )
Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the `HTTP_PROXY` environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an `httpoxy` issue.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Twistedmatrix Twisted | <16.3.1 | |
pip/twisted | <16.3.1 | 16.3.1 |
Twisted Twisted | <16.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this CVE is CVE-2016-1000111.
The severity level of CVE-2016-1000111 is medium (5.3).
CVE-2016-1000111 affects Twisted before version 16.3.1.
The CWE ID associated with CVE-2016-1000111 is CWE-425.
Yes, you can find references for CVE-2016-1000111 at the following links: - [NVD](https://nvd.nist.gov/vuln/detail/CVE-2016-1000111) - [Twistedmatrix](https://twistedmatrix.com/pipermail/twisted-web/2016-August/005268.html) - [Twistedmatrix Trac](https://twistedmatrix.com/trac/ticket/8623)