erlang: allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy serve
Published Dec 10, 2019
6.1
MEDIUMCVSS 3.1
EPSS 1.42%
Description
inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue.
Affected products
No data.
- ≤ 22.1
No data.
CloudForms Management Engine 5
erlang
Not affected
Red Hat Ansible Tower 3
erlang
Not affected
Red Hat OpenStack Platform 10 (Newton)
erlang
Will not fix
Red Hat OpenStack Platform 13 (Queens)
erlang
Will not fix
Red Hat OpenStack Platform 15 (Stein)
erlang
Will not fix
Red Hat OpenStack Platform 16 (Train)
erlang
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5 | erlang | Not affected | n/a |
| Red Hat Ansible Tower 3 | erlang | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | erlang | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | erlang | Will not fix | n/a |
| Red Hat OpenStack Platform 15 (Stein) | erlang | Will not fix | n/a |
| Red Hat OpenStack Platform 16 (Train) | erlang | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat CloudFroms 5.10 ship affected Erlang package, however, CloudFroms uses it as a dependency for Ansible Tower and do not expose it anywhere in product. Furthermore, Ansible Tower does not pass environment variables to RabbitMQ or Erlang which makes it not affected. Red Hat OpenStack Platform ships the affected Erlang package, however it is only used as a dependency for RabbitMQ and is not exposed outside the management network. As this network is tightly-regulated to OpenStack administrators, the risk for abuse is significantly reduced.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 1.42% (0.01417) | 71.83th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.43% (0.01428) | 69.42th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.42% (0.00422) | 59.18th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.43% (0.01434) | 68.70th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.42% (0.00422) | 59.98th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.21% (0.00209) | 59.78th | v3 (v2023.03.01) |
| Jun 15, 2024 | 0.24% (0.00239) | 62.09th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.24% (0.00239) | 60.08th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.21% (0.01213) | 66.61th | v2 (v2022.01.01) |
| Feb 17, 2023 | 1.21% (0.01213) | 66.22th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.21% (0.01213) | 64.21th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.21% (0.01213) | 40.54th | v2 (v2022.01.01) |
References (8)
- http://www.openwall.com/lists/oss-security/2016/07/18/6 x_refsource_MISCMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2016-1000107 Vendor Advisory
- https://bugs.erlang.org/browse/ERL-198 x_refsource_MISCIssue TrackingVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1824460 Issue Tracking
- https://httpoxy.org/ x_refsource_MISCThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-1000107
- https://security-tracker.debian.org/tracker/CVE-2016-1000107 x_refsource_MISCThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2016-1000107
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2016/07/18/6 | x_refsource_MISCMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2016-1000107 | Vendor Advisory | |
| https://bugs.erlang.org/browse/ERL-198 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1824460 | Issue Tracking | |
| https://httpoxy.org/ | x_refsource_MISCThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2016-1000107 | ||
| https://security-tracker.debian.org/tracker/CVE-2016-1000107 | x_refsource_MISCThird Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2016-1000107 |
Change history (0)
No recorded changes yet.