Apache Tomcat HTTP_PROXY environment variable Security Vulnerability (CVE-2016-5388)
Apache Tomcat HTTP_PROXY environment variable Security Vulnerability (CVE-2016-5388)
Release date:
Updated on:
Affected Systems:
Apache Group Tomcat < 8.5.4
Description:
CVE (CAN) ID: CVE-2016-5388
Apache Tomcat is a popular open-source JSP application server program.
When CGI Servlet is enabled in Apache Tomcat <8.5.4, there is a namespace conflict in RFC 3875 section 4.1.18, And the HTTP_PROXY environment variable cannot filter the constructed client data. Remote attackers can construct the Proxy header of an HTTP request to redirect the HTTP data stream of an application to any Proxy server.
<* Source: Dominic Scheirlinck
Scott Geary
*>
Suggestion:
Vendor patch:
Apache Group
------------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://httpd.apache.org/
Refer:
Https://www.apache.org/security/asf-httpoxy-response.txt
Http://www.kb.cert.org/vuls/id/797896
Https://httpoxy.org/
For more Tomcat tutorials, see the following:
Install and configure the Tomcat environment in CentOS 6.6
Install JDK + Tomcat in RedHat Linux 5.5 and deploy Java Projects
Tomcat authoritative guide (second edition) (Chinese/English hd pdf + bookmarks)
Tomcat Security Configuration and Performance Optimization
How to Use Xshell to view Tomcat real-time logs with Chinese garbled characters in Linux
Install JDK and Tomcat in CentOS 64-bit and set the Tomcat Startup Procedure
Install Tomcat in CentOS 6.5
Tomcat details: click here
Tomcat: click here
This article permanently updates the link address: