CVE-2016-5386
Aliases:GO-2022-0761
Advisory lineage Upstream: 0 Downstream: 12
Modified
Published: 19 Jul 2016, 01:00
Last modified:06 Aug 2024, 01:00
Vulnerability Summary
Overall Risk (default)
medium
42/100 CVSS Score
8.1 HIGH
v3.1 (nvd)
EPSS Score
45.9% HIGH
46% probability -35.65%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
19 Jul 2016, 01:00
Published
Vulnerability first disclosed
06 Aug 2024, 01:00
Last Modified
Vulnerability information updated
Description
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
CVSS Metrics
- v3.1•HIGH•Score: 8.1CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- v2.0•MEDIUM•Score: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 45.90%• Percentile: 98%
Techniques & Countermeasures
- CWE-284•Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
Affected Systems
- fedoraproject•fedora
23 | 24
- golang•go
≥ 1.0, < 1.6.3 | 1.7:rc1
- Go•stdlib
< 1.6.3
- oracle•linux
7
- redhat•enterprise_linux_server
7.0
- redhat•enterprise_linux_server_aus
7.2
- redhat•enterprise_linux_server_eus
7.2
References (13)
- http://www.kb.cert.org/vuls/id/797896
- https://bugzilla.redhat.com/show_bug.cgi?id=1353798
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WGHKKCFP4PLVSWQKCM3FJJPEWB5ZNTU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/OR52UXGM6RKSCWF3KQMVZGVZVJ3WEESJ/
- http://rhn.redhat.com/errata/RHSA-2016-1538.html
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03770en_us
- https://httpoxy.org/
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- https://go.dev/cl/25010
- https://go.googlesource.com/go/+/b97df54c31d6c4cc2a28a3c83725366d52329223
- https://go.dev/issue/16405
- https://groups.google.com/g/golang-announce/c/7jZDOQ8f8tM/m/eWRWHnc8CgAJ