U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2016-5388

Change History

CVE Modified by Red Hat, Inc. 2/12/2023 6:23:33 PM

Action Type Old Value New Value
Removed CVSS V2
Red Hat, Inc. (AV:N/AC:H/Au:N/C:N/I:P/A:N)

								
						
Removed CVSS V3
Red Hat, Inc. AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N

								
						
Changed Description
It was discovered that tomcat used the value of the Proxy header from HTTP requests to initialize the HTTP_PROXY environment variable for CGI scripts, which in turn was incorrectly used by certain HTTP client implementations to configure the proxy for outgoing HTTP requests. A remote attacker could possibly use this flaw to redirect HTTP requests performed by a CGI script to an attacker-controlled proxy via a malicious HTTP request.
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "A mitigation is planned for future releases of Tomcat, tracked as CVE-2016-5388"; in other words, this is not a CVE ID for a vulnerability.
Removed Reference
https://access.redhat.com/errata/RHSA-2016:1624 [No Types Assigned]

								
						
Removed Reference
https://access.redhat.com/errata/RHSA-2016:2045 [No Types Assigned]

								
						
Removed Reference
https://access.redhat.com/errata/RHSA-2016:2046 [No Types Assigned]

								
						
Removed Reference
https://access.redhat.com/security/cve/CVE-2016-5388 [No Types Assigned]

								
						
Removed Reference
https://bugzilla.redhat.com/show_bug.cgi?id=1353809 [No Types Assigned]