The spiffy-cgi-handlers egg would convert a nonexistent Proxy header to the HTTP_PROXY environment variable, which would allow attackers to direct CGI programs which use this environment variable to use an attacker-specified HTTP proxy server (also known as a httpoxy attack). This affects all versions of spiffy-cgi-handlers before 0.5.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Http-client | Call-cc | * | 0.4.2 (including) |