CVE-2016-6287: High severity call-cc http-client vulnerability
The "http-client" egg always used a HTTPPROXY environment variable to determine whether HTTP traffic should be routed via a proxy, even when running as a CGI process. Under several web servers this would mean a user-supplied "Proxy" header could allow an attacker to direct all HTTP requests through a proxy (also known as a "httpoxy" attack). This affects all versions of http-client before 0.10.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6287?
CVE-2016-6287 has a medium severity rating due to the potential for an attacker to manipulate HTTP traffic.
How do I fix CVE-2016-6287?
To fix CVE-2016-6287, upgrade to a version of the 'http-client' egg newer than 0.9.
What does CVE-2016-6287 affect?
CVE-2016-6287 affects the 'http-client' egg from Call-cc versions up to and including 0.9.
What kind of attack is possible with CVE-2016-6287?
CVE-2016-6287 allows an attacker to redirect HTTP requests through a malicious proxy using the Proxy header.
When was CVE-2016-6287 disclosed?
CVE-2016-6287 was disclosed in July 2016.