Input validation error in Netty and Play Framework - CVE-2015-2156

 

Input validation error in Netty and Play Framework - CVE-2015-2156

Published: October 18, 2017 / Updated: August 8, 2020


Vulnerability identifier: #VU38060
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2015-2156
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Netty project
Jenkins
Affected software:
Netty
Play Framework

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.


How to mitigate CVE-2015-2156

Install update from vendor's website.

Sources