Skip to content

"HTTPoxy", use of HTTP_PROXY flag supplied by attacker in CGI scripts #71755

@remram44

Description

@remram44
mannequin
BPO 27568
Nosy @jcea, @orsenthil, @encukou, @vadmium, @sigmavirus24, @Lukasa, @remram44
Files
  • python-2.7-httpoxy.patch
  • python-3.5-httpoxy.patch
  • Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

    Show more details

    GitHub fields:

    assignee = 'https://github.com/orsenthil'
    closed_at = <Date 2016-07-31.06:57:15.341>
    created_at = <Date 2016-07-18.22:30:13.775>
    labels = ['type-security', 'library']
    title = '"HTTPoxy", use of HTTP_PROXY flag supplied by attacker in CGI scripts'
    updated_at = <Date 2016-08-11.03:10:11.407>
    user = 'https://github.com/remram44'

    bugs.python.org fields:

    activity = <Date 2016-08-11.03:10:11.407>
    actor = 'jcea'
    assignee = 'orsenthil'
    closed = True
    closed_date = <Date 2016-07-31.06:57:15.341>
    closer = 'orsenthil'
    components = ['Library (Lib)']
    creation = <Date 2016-07-18.22:30:13.775>
    creator = 'remram'
    dependencies = []
    files = ['43943', '43944']
    hgrepos = []
    issue_num = 27568
    keywords = ['patch']
    message_count = 17.0
    messages = ['270795', '270800', '270811', '270819', '270840', '270844', '270854', '270901', '271617', '271624', '271658', '271687', '271688', '271725', '271726', '271893', '272104']
    nosy_count = 9.0
    nosy_names = ['jcea', 'orsenthil', 'frispete', 'petr.viktorin', 'python-dev', 'martin.panter', 'icordasc', 'Lukasa', 'remram']
    pr_nums = []
    priority = 'normal'
    resolution = 'fixed'
    stage = 'resolved'
    status = 'closed'
    superseder = None
    type = 'security'
    url = 'https://bugs.python.org/issue27568'
    versions = ['Python 2.7', 'Python 3.3', 'Python 3.4', 'Python 3.5', 'Python 3.6']

    Metadata

    Metadata

    Assignees

    Labels

    stdlibStandard Library Python modules in the Lib/ directorytype-securityA security issue

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions