Input validation error in Play Framework and Netty - CVE-2015-2156
Published: October 18, 2017 / Updated: August 8, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.
Affected software
Netty
IBM PureData System for Operational Analytics
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Spectrum Protect Plus
Operations Analytics - Log Analysis
StreamSets Data Collector
Fedora
watsonx.data
netty
How to mitigate CVE-2015-2156
watsonx.data - update to 2.0.2
netty - addressed in versions 4.0.28-1.fc21, 4.0.28-1.fc22
IBM Watson Knowledge Catalog in Cloud Pak for Data - update to 4.8.0
StreamSets Data Collector - update to 7.0.0
IBM Spectrum Protect Plus - update to 10.1.6.4
External References
- http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159379.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-May/159166.html
- http://netty.io/news/2015/05/08/3-9-8-Final-and-3.html
- http://www.openwall.com/lists/oss-security/2015/05/17/1
- http://www.securityfocus.com/bid/74704
- https://bugzilla.redhat.com/show_bug.cgi?id=1222923
- https://github.com/netty/netty/pull/3754
- https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E
- https://lists.apache.org/thread.html/a19bb1003b0d6cd22475ba83c019b4fc7facfef2a9e13f71132529d3@%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/dc1275aef115bda172851a231c76c0932d973f9ffd8bc375c4aba769@%3Ccommits.cassandra.apache.org%3E
- https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E
- https://www.playframework.com/security/vulnerability/CVE-2015-2156-HttpOnlyBypass
Related Security Bulletins
- Input validation error in Netty
- Multiple vulnerabilities in IBM PureData System for Operational Analytics
- Multiple vulnerabilities in IBM Watson Knowledge Catalog on-prem
- Multiple vulnerabilities in IBM watsonx.data
- Multiple vulnerabilities in IBM Spectrum Protect Plus
- Fedora 22 update for netty
- Fedora 21 update for netty
- Multiple vulnerabilities in IBM StreamSets Data Collector
- Multiple vulnerabilities in IBM Operations Analytics - Log Analysis