mirror of
https://github.com/python/cpython.git
synced 2025-08-04 00:48:58 +00:00
Prevent HTTPoxy attack (CVE-2016-1000110)
Ignore the HTTP_PROXY variable when REQUEST_METHOD environment is set, which indicates that the script is in CGI mode. Issue #27568 Reported and patch contributed by Rémi Rampin.
This commit is contained in:
parent
d27a7c1f22
commit
4cbb23f8f2
5 changed files with 42 additions and 0 deletions
|
@ -2366,6 +2366,13 @@ def getproxies_environment():
|
|||
name = name.lower()
|
||||
if value and name[-6:] == '_proxy':
|
||||
proxies[name[:-6]] = value
|
||||
|
||||
# CVE-2016-1000110 - If we are running as CGI script, forget HTTP_PROXY
|
||||
# (non-all-lowercase) as it may be set from the web server by a "Proxy:"
|
||||
# header from the client
|
||||
if 'REQUEST_METHOD' in os.environ:
|
||||
proxies.pop('http', None)
|
||||
|
||||
return proxies
|
||||
|
||||
def proxy_bypass_environment(host):
|
||||
|
|
Loading…
Add table
Add a link
Reference in a new issue