Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-2156

Опубликовано: 09 мая 2015
Источник: redhat
CVSS2: 2.6
EPSS Низкий

Описание

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6nettyNot affected
Red Hat JBoss BRMS 5nettyWill not fix
Red Hat JBoss BRMS 6nettyAffected
Red Hat JBoss Data Grid 6nettyAffected
Red Hat JBoss Data Virtualization 6nettyAffected
Red Hat JBoss Enterprise Application Platform 5nettyAffected
Red Hat JBoss Enterprise Application Platform 6nettyAffected
Red Hat JBoss Enterprise Web Server 1eds-5Will not fix
Red Hat JBoss Enterprise Web Server 1ewp-5Not affected
Red Hat JBoss Enterprise Web Server 1fuse-6Affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-20

EPSS

Процентиль: 87%
0.03271
Низкий

2.6 Low

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.

CVSS3: 7.5
nvd
больше 8 лет назад

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.

CVSS3: 7.5
debian
больше 8 лет назад

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0 ...

CVSS3: 7.5
github
больше 5 лет назад

Information Exposure in Netty

EPSS

Процентиль: 87%
0.03271
Низкий

2.6 Low

CVSS2