The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 30, 2017 | Jul 19, 2016 |
| Amazon_linux | — | Upgrade httpdUpgrade httpd24 | Jul 22, 2016 | Jul 18, 2016 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Jul 27, 2016 | Jul 19, 2016 |
| Apple Osx Apache | — | Apply OS X security update 2017-001 SierraApply OS X security update 2017-004 El CapitanUpgrade macOS to the latest version | Mar 28, 2017 | Jul 18, 2016 |
| Centos_linux | — | Upgrade mod_ldapUpgrade httpd-develUpgrade mod_sessionUpgrade httpdUpgrade httpd-manualUpgrade mod_proxy_htmlUpgrade mod_sslUpgrade httpd-tools | Jul 22, 2016 | Jul 18, 2016 |
| Debian | — | Upgrade apache2 | Jul 20, 2016 | Jul 18, 2016 |
| Freebsd | — | Upgrade apache24 | Dec 21, 2016 | Dec 21, 2016 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Oct 30, 2017 | Jul 18, 2016 |
| Hpsmh | — | Upgrade to the latest version of HP System Management Homepage | Oct 27, 2016 | Jul 18, 2016 |
| Huawei Euleros 2_0_sp1 | — | Upgrade httpdUpgrade httpd-develUpgrade httpd-manualUpgrade httpd-toolsUpgrade mod_ssl | Nov 30, 2017 | Jul 18, 2016 |
| Ibm Http_server | — | Apply IBM HTTP Server Interim Fix PI66849Apply IBM HTTP Server version 7.0.0.43 or laterApply IBM HTTP Server version 8.0.0.13 or laterApply IBM HTTP Server version 8.5.5.11 or laterApply IBM HTTP Server version 9.0.0.1 or later | Sep 7, 2022 | Sep 7, 2022 |
| Oracle Solaris | — | Upgrade web/server/apache-22/module/apache-sed to version 2.2.31-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-22/documentation to version 2.2.31-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-24 to version 2.4.23-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-dbd to version 2.4.23-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ldap to version 2.4.23-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-lua to version 2.4.23-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl to version 2.4.23-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-24/module/apache-ssl-fips-140 to version 2.4.23-0.175.3.13.0.1.0 on Solaris 11.3Upgrade web/server/apache-22 to version 2.2.31-0.175.3.13.0.1.0 on Solaris 11.3 | May 29, 2017 | Jul 18, 2016 |
| Oracle_linux | — | Upgrade httpd-manualUpgrade mod_ldapUpgrade mod_sslUpgrade mod_sessionUpgrade mod_proxy_htmlUpgrade httpd-toolsUpgrade httpdUpgrade httpd-devel | Jul 18, 2016 | Jul 18, 2016 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Jul 18, 2016 |
| Redhat_linux | — | Upgrade mod_ldapUpgrade httpd-toolsUpgrade mod_sessionUpgrade mod_sslUpgrade httpd-develUpgrade httpd-manualUpgrade httpd-debuginfoUpgrade mod_proxy_htmlUpgrade httpd | Jul 29, 2016 | Jul 18, 2016 |
| Suse | — | Upgrade apache2-develUpgrade apache2-example-pagesUpgrade apache2-preforkUpgrade apache2-eventUpgrade apache2Upgrade apache2-worker | Jul 26, 2016 | Jul 18, 2016 |
| Ubuntu | — | Upgrade apache2.2-binUpgrade apache2-bin | Jul 18, 2016 | Jul 18, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub