The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade python27Upgrade python26Upgrade python34 | Sep 2, 2016 | Aug 18, 2016 |
| Centos_linux | — | Upgrade pythonUpgrade python-testUpgrade tkinterUpgrade python-toolsUpgrade python-debugUpgrade python-libsUpgrade python-devel | Aug 22, 2016 | Aug 18, 2016 |
| Debian | — | Upgrade python2.7 | Jul 30, 2024 | Nov 27, 2019 |
| Oracle_linux | — | Upgrade python-libsUpgrade python-testUpgrade python-develUpgrade tkinterUpgrade python-toolsUpgrade python-debugUpgrade python | Aug 22, 2016 | Jul 18, 2016 |
| Redhat_linux | — | Upgrade pythonUpgrade python-libsUpgrade tkinterUpgrade python-testUpgrade python-debuginfoUpgrade python-develUpgrade python-toolsUpgrade python-debugNo solution exists | Aug 22, 2016 | Aug 18, 2016 |
| Suse | — | Upgrade python-32bitUpgrade python-develUpgrade python-doc-pdfUpgrade python3-tkUpgrade python3-develUpgrade libpython2_6-1_0Upgrade python-x86Upgrade python-base-32bitUpgrade python3-cursesUpgrade python3-base-32bitUpgrade python3-testsuiteUpgrade libpython3_6m1_0Upgrade python-tkUpgrade libpython2_7-1_0Upgrade python-cursesUpgrade python-gdbmUpgrade python-xmlUpgrade pythonUpgrade python-idleUpgrade python3Upgrade libpython2_7-1_0-32bitUpgrade libpython2_6-1_0-x86Upgrade python3-toolsUpgrade python3-baseUpgrade python-docUpgrade python3-32bitUpgrade python-base-x86Upgrade libpython2_6-1_0-32bitUpgrade libpython3_6m1_0-32bitUpgrade python3-idleUpgrade python-demoUpgrade libpython3_4m1_0-32bitUpgrade python3-dbmUpgrade python-baseUpgrade libpython3_4m1_0 | Aug 22, 2016 | Aug 18, 2016 |
| Ubuntu | — | Upgrade libpython3.5-stdlibUpgrade python3.2-minimalUpgrade libpython3.5Upgrade python3.5Upgrade libpython3.4Upgrade libpython2.7Upgrade python3.4-minimalUpgrade python3.4Upgrade libpython3.4-stdlibUpgrade python2.7Upgrade libpython3.5-minimalUpgrade libpython2.7-stdlibUpgrade python2.7-minimalUpgrade libpython3.4-minimalUpgrade python3.2Upgrade libpython3.2Upgrade python3.5-minimalUpgrade libpython2.7-minimal | Nov 23, 2016 | Aug 18, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub