Prevent HTTPoxy attack (CVE-2016-1000110)

Ignore the HTTP_PROXY variable when REQUEST_METHOD environment is set, which
indicates that the script is in CGI mode.

Issue #27568 Reported and patch contributed by Rémi Rampin.
This commit is contained in:
Senthil Kumaran 2016-07-30 23:24:16 -07:00
parent d27a7c1f22
commit 4cbb23f8f2
5 changed files with 42 additions and 0 deletions

View file

@ -2366,6 +2366,13 @@ def getproxies_environment():
name = name.lower()
if value and name[-6:] == '_proxy':
proxies[name[:-6]] = value
# CVE-2016-1000110 - If we are running as CGI script, forget HTTP_PROXY
# (non-all-lowercase) as it may be set from the web server by a "Proxy:"
# header from the client
if 'REQUEST_METHOD' in os.environ:
proxies.pop('http', None)
return proxies
def proxy_bypass_environment(host):