mirror of
https://github.com/python/cpython.git
synced 2025-07-24 19:54:21 +00:00
[merge from 3.3] Prevent HTTPoxy attack (CVE-2016-1000110)
Ignore the HTTP_PROXY variable when REQUEST_METHOD environment is set, which indicates that the script is in CGI mode. Issue #27568 Reported and patch contributed by Rémi Rampin.
This commit is contained in:
commit
436fe5a447
5 changed files with 42 additions and 0 deletions
|
@ -538,6 +538,11 @@ setting up a `Basic Authentication`_ handler: ::
|
|||
through a proxy. However, this can be enabled by extending urllib.request as
|
||||
shown in the recipe [#]_.
|
||||
|
||||
.. note::
|
||||
|
||||
`HTTP_PROXY`` will be ignored if a variable ``REQUEST_METHOD`` is set; see
|
||||
the documentation on :func:`~urllib.request.getproxies`.
|
||||
|
||||
|
||||
Sockets and Layers
|
||||
==================
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue