CVE-2016-5386

Aliases:GO-2022-0761
Modified
Published: 19 Jul 2016, 01:00
Last modified:06 Aug 2024, 01:00

Vulnerability Summary

Overall Risk (default)
medium
42/100
CVSS Score
8.1 HIGH
v3.1 (nvd)
EPSS Score
45.9% HIGH
46% probability -35.65%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Jul 2016, 01:00
Published
Vulnerability first disclosed
06 Aug 2024, 01:00
Last Modified
Vulnerability information updated

Description

The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.

CVSS Metrics

  • v3.1HIGHScore: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 45.90% Percentile: 98%

Techniques & Countermeasures

  • CWE-284Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Affected Systems

  • fedoraprojectfedora

    23 | 24

  • golanggo

    ≥ 1.0, < 1.6.3 | 1.7:rc1

  • Gostdlib

    < 1.6.3

  • oraclelinux

    7

  • redhatenterprise_linux_server

    7.0

  • redhatenterprise_linux_server_aus

    7.2

  • redhatenterprise_linux_server_eus

    7.2

References (13)