SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-5386

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might…

HIGH 8.1EPSS 5.22%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (5.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
5.22% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-284
Affected
fedoraproject/fedora · oracle/linux · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · golang/go
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.