CVE-2016-5386
Improper input validation in net/http and net/http/cgi
EPSS 5.2%
描述
An input validation flaw in the CGI components allows the HTTP_PROXY environment variable to be set by the incoming Proxy header, which changes where Go by default proxies all outbound HTTP requests. This environment variable is also used to set the outgoing proxy, enabling an attacker to insert a proxy into outgoing requests of a CGI program. Read more about "httpoxy" here: https://httpoxy.org.
如何修補 CVE-2016-5386
要修補 CVE-2016-5386,請將受影響套件升級到下列已修補版本。
- Go/stdlib—升級至 1.6.3 或更新版本
CVE-2016-5386 正在被利用嗎?
中等 — EPSS 為 5.2%,可持續追蹤但非最高優先。
受影響套件(1)
- from 0, < 1.6.3