Input validation error in Netty and Play Framework - CVE-2015-2156

 

Input validation error in Netty and Play Framework - CVE-2015-2156

Published: October 18, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38060
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2015-2156
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Netty
Play Framework
Software vendor:
Netty project
Jenkins

Description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.


Remediation

Install update from vendor's website.

External links