CVE-2016-4694, also known as an "httpoxy" issue, affects Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2. This vulnerability allows remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server. It achieves this by exploiting the server's adherence to RFC 3875, which permits untrusted CGI client data in the HTTP_PROXY environment variable. The vulnerability carries a critical CVSS score of 9.1, indicating a severe risk. It is easily exploitable over the network with low attack complexity, requiring no user interaction or privileges. A successful exploit could lead to high confidentiality and integrity impacts, as attackers could intercept or manipulate an application's HTTP traffic. There is no evidence of active exploitation, and no public exploit code is available for this CVE, including Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, suggesting a lack of widespread attention or current exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 10.11.6CPE matchmatch criteria | cpe:2.3:o:apple:mac_os_x:*:*:*:*:*:*:*:* | ||
<= 5.1CPE matchmatch criteria | cpe:2.3:o:apple:os_x_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.