Back

HIGH

mod_fcgid: mod_fcgid sets environmental variable based on user supplied Proxy request header

Published Dec 3, 2019

Description

A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.

Affected products

Remediation

Red Hat statement

This issue is addressed through the Apache HTTPD update for CVE-2016-5387 which prevent the Proxy header from automatically being converted into the HTTP_PROXY environmental variable. Unless the "FcgidPassHeader Proxy" is used mod_fcgid is not vulnerable to this attack when used with updated HTTPD. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Metrics

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 3, 2019
Updated Aug 6, 2024
Reserved Jul 18, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 18, 2016