|
|
Log in / Subscribe / Register

tomcat: redirect HTTP traffic

Package(s):tomcat CVE #(s):CVE-2016-5388
Created:September 7, 2016 Updated:November 3, 2016
Description: From the CVE entry:

Apache Tomcat through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "A mitigation is planned for future releases of Tomcat, tracked as CVE-2016-5388"; in other words, this is not a CVE ID for a vulnerability.

Alerts:
Fedora FEDORA-2016-4094bd4ad6 tomcat 2016-11-13
Fedora FEDORA-2016-c1b01b9278 tomcat 2016-11-12
Arch Linux ASA-201611-6 tomcat6 2016-11-02
Scientific Linux SLSA-2016:2045-1 tomcat6 2016-10-11
Scientific Linux SLSA-2016:2046-1 tomcat 2016-10-11
CentOS CESA-2016:2045 tomcat6 2016-10-11
CentOS CESA-2016:2046 tomcat 2016-10-11
Oracle ELSA-2016-2045 tomcat6 2016-10-10
Red Hat RHSA-2016:2045-01 tomcat6 2016-10-10
Red Hat RHSA-2016:2046-01 tomcat 2016-10-10
Mageia MGASA-2016-0312 tomcat 2016-09-21
Arch Linux ASA-201609-21 tomcat7 2016-09-22
Arch Linux ASA-201609-7 tomcat8 2016-09-10
openSUSE openSUSE-SU-2016:2252-1 tomcat 2016-09-06
Ubuntu USN-3177-2 tomcat 2017-02-02
Ubuntu USN-3177-1 tomcat6, tomcat7, tomcat8 2017-01-23
Fedora FEDORA-2016-38e5b05260 tomcat 2016-11-19

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds