--- layout: post status: PUBLISHED published: true title: '"httpoxy" CGI vulnerability response' id: 36b0bc68-b252-493d-9b87-3fe28057d787 date: '2016-07-20 15:53:16 -0400' categories: foundation tags: - http - httpoxy - vulerability permalink: foundation/entry/httpoxy_cgi_vulnerability_response ---

A group of ASF projects (HTTP Server, Tomcat, Traffic Server, mod_perl) has analyzed the CGI application vulnerability recently published at https://httpoxy.org/

Their detailed analysis, targeted at Web server administrators and CGI developers and including mitigation information, can be found at https://www.apache.org/security/asf-httpoxy-response.txt