CVE-2015-2156
Last modified
CVE-2015-2156 is a vulnerability of currently unknown severity. Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.. EPSS estimates a 5.43% chance of exploitation in the next 30 days.
Description
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Netty | Netty | <= 3.9.7 | — |
| Netty | Netty | 3.10.0 | — |
| Netty | Netty | 3.10.1 | — |
| Netty | Netty | 3.10.2 | — |
| Netty | Netty | 4.0.0 | — |
| Netty | Netty | 4.0.1 | — |
| Netty | Netty | 4.0.2 | — |
| Netty | Netty | 4.0.3 | — |
| Netty | Netty | 4.0.4 | — |
| Netty | Netty | 4.0.5 | — |
| Netty | Netty | 4.0.6 | — |
| Netty | Netty | 4.0.7 | — |
| Netty | Netty | 4.0.8 | — |
| Netty | Netty | 4.0.9 | — |
| Netty | Netty | 4.0.10 | — |
| Netty | Netty | 4.0.11 | — |
| Netty | Netty | 4.0.12 | — |
| Netty | Netty | 4.0.13 | — |
| Netty | Netty | 4.0.14 | — |
| Netty | Netty | 4.0.15 | — |
| Netty | Netty | 4.0.16 | — |
| Netty | Netty | 4.0.17 | — |
| Netty | Netty | 4.0.18 | — |
| Netty | Netty | 4.0.19 | — |
| Netty | Netty | 4.0.20 | — |
| Netty | Netty | 4.0.21 | — |
| Netty | Netty | 4.0.22 | — |
| Netty | Netty | 4.0.23 | — |
| Netty | Netty | 4.0.24 | — |
| Netty | Netty | 4.0.25 | — |
| Netty | Netty | 4.0.26 | — |
| Netty | Netty | 4.0.27 | — |
| Netty | Netty | 4.1.0 | Beta1 |
| Lightbend | Play Framework | 2.0 | Rc3 |
| Lightbend | Play Framework | 2.0.2 | — |
| Lightbend | Play Framework | 2.0.3 | — |
| Lightbend | Play Framework | 2.0.4 | — |
| Lightbend | Play Framework | 2.0.5 | — |
| Lightbend | Play Framework | 2.0.6 | — |
| Lightbend | Play Framework | 2.0.7 | — |
| Lightbend | Play Framework | 2.0.8 | — |
| Lightbend | Play Framework | 2.1.0 | — |
| Lightbend | Play Framework | 2.1.1 | — |
| Lightbend | Play Framework | 2.2.0 | — |
| Lightbend | Play Framework | 2.2.1 | — |
| Lightbend | Play Framework | 2.2.2 | — |
| Lightbend | Play Framework | 2.2.6 | — |
| Lightbend | Play Framework | 2.3.0 | — |
| Lightbend | Play Framework | 2.3.1 | — |
| Lightbend | Play Framework | 2.3.2 | — |
Showing 50 of 71 affected configurations. See NVD for the full list.
References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159379.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159166.htmlThird Party Advisory
- http://netty.io/news/2015/05/08/3-9-8-Final-and-3.htmlVendor Advisory
- http://www.openwall.com/lists/oss-security/2015/05/17/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/74704Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1222923Issue Tracking, Third Party Advisory
- https://github.com/netty/netty/pull/3754Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159379.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159166.htmlThird Party Advisory
- http://netty.io/news/2015/05/08/3-9-8-Final-and-3.htmlVendor Advisory
- http://www.openwall.com/lists/oss-security/2015/05/17/1Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/74704Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1222923Issue Tracking, Third Party Advisory
- https://github.com/netty/netty/pull/3754Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-2156?
How severe is CVE-2015-2156?
How do I fix CVE-2015-2156?
Are you affected by CVE-2015-2156?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
