Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:17577
HistoryMay 02, 2019 - 5:46 a.m.

Open Redirection

2019-05-0205:46:32
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.226

Percentile

96.6%

python is vulnerable to Open Redirection vulnerability. The vulnerability exists because Python CGIHandler class does not properly protect against the HTTP_PROXY variable name clash in a CGI context. Remote attackers could redirect HTTP requests performed by a Python CGI script to an attacker-controlled proxy via a malicious HTTP request and hence view potentially sensitive information, reply with malformed data, or to hold connections open causing a potential denial of service.