VDB
Sign up
HIGH8.1

GHSA-m6ch-gg5f-wxx3

HTTP Proxy header vulnerability

Quick fix

GHSA-m6ch-gg5f-wxx3 — guzzlehttp/guzzle: upgrade to the fixed version with the command below.

composer require guzzlehttp/guzzle:^6.2.1

Details

PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/guzzlehttp/guzzle
Introduced in: 6Fixed in: 6.2.1
Fixcomposer require guzzlehttp/guzzle:^6.2.1
Packagist/guzzlehttp/guzzle
Introduced in: 4.0.0-rc2Fixed in: 4.2.4
Fixcomposer require guzzlehttp/guzzle:^4.2.4
Packagist/guzzlehttp/guzzle
Introduced in: 5Fixed in: 5.3.1
Fixcomposer require guzzlehttp/guzzle:^5.3.1
Packagist/drupal/core
Introduced in: 8.0Fixed in: 8.1.7
Fixcomposer require drupal/core:^8.1.7
Packagist/bugsnag/bugsnag-laravel
Introduced in: 0Fixed in: 2.0.2
Fixcomposer require bugsnag/bugsnag-laravel:^2.0.2
Packagist/amphp/artax
Introduced in: 0Fixed in: 1.0.4
Fixcomposer require amphp/artax:^1.0.4
Packagist/amphp/artax
Introduced in: 2.0.0Fixed in: 2.0.4
Fixcomposer require amphp/artax:^2.0.4
Packagist/padraic/humbug_get_contents
Introduced in: 0Fixed in: 1.1.2
Fixcomposer require padraic/humbug_get_contents:^1.1.2

References