Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-2156

Опубликовано: 18 окт. 2017
Источник: debian

Описание

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
netty3.1removedpackage
netty3.1no-dsawheezypackage
nettyfixed1:4.0.31-1package
nettyignoredjessiepackage
nettyno-dsawheezypackage
nettyno-dsasqueezepackage
netty-3.9fixed3.9.9.Final-1package
netty-3.9ignoredjessiepackage
playframeworkitppackage

Примечания

  • http://netty.io/news/2015/05/08/3-9-8-Final-and-3.html

  • https://www.playframework.com/security/vulnerability/CVE-2015-2156-HttpOnlyBypass

  • http://web.archive.org/web/20150925094949/http://engineering.linkedin.com/security/look-netty%E2%80%99s-recent-security-update-cve%C2%AD-2015%C2%AD-2156

  • https://github.com/netty/netty/commit/97d871a7553a01384b43df855dccdda5205ae77a

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.

redhat
больше 10 лет назад

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.

CVSS3: 7.5
nvd
больше 8 лет назад

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.

CVSS3: 7.5
github
больше 5 лет назад

Information Exposure in Netty