Alpine: multiple py3-twisted packages: security update to 16.4.0-r0

medium Tenable Self-Hosted Container Security Plugin ID 406709

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Twisted before 16.3.1 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and
therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY
environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP
traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy"
issue. (CVE-2016-1000111)

See Also

https://security.alpinelinux.org/vuln/CVE-2016-1000111

Plugin Details

Severity: Medium

ID: 406709

Version: Revision 1.28

Type: Local

Published: 10/31/2023

Updated: 12/4/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

CVSS Score Source: CVE-2016-1000111

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 2.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 7/18/2016

Reference Information

CVE: CVE-2016-1000111

BID: 91820