CVE-2015-2156
published 2017-10-18CVE-2015-2156: Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow…
PriorityP344high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
5.43%
91.8th percentile
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.
Affected
76 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | netty | < netty 1:4.0.31-1 (bookworm) | netty 1:4.0.31-1 (bookworm) |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| lightbend | play_framework | — | — |
| netty | netty | <= 3.9.7 | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Information Exposure in Netty
osv·2020-06-30
CVE-2015-2156 [HIGH] Information Exposure in Netty
Information Exposure in Netty
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.
GHSA
Information Exposure in Netty
ghsa·2020-06-30
CVE-2015-2156 [HIGH] CWE-20 Information Exposure in Netty
Information Exposure in Netty
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.
OSV
CVE-2015-2156: Netty before 3
osv·2017-10-18·CVSS 7.5
CVE-2015-2156 [HIGH] CVE-2015-2156: Netty before 3
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.
Red Hat
netty: HttpOnly cookie bypass
vendor_redhat·2015-05-09·CVSS 7.5
CVE-2015-2156 [HIGH] CWE-20 netty: HttpOnly cookie bypass
netty: HttpOnly cookie bypass
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.
Package: netty (Red Hat BPM Suite 6) - Not affected
Package: netty (Red Hat JBoss BRMS 5) - Will not fix
Package: netty (Red Hat JBoss BRMS 6) - Affected
Package: netty (Red Hat JBoss Data Grid 6) - Affected
Package: netty (Red Hat JBoss Data Virtualization 6) - Affected
Package: netty (Red Hat JBoss Enterprise Application Platform 5) - Affected
Package: netty (Red Hat JBoss Enterprise Application Platform 6) - Affected
Package: netty (Red
Debian
CVE-2015-2156: netty - Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final,...
vendor_debian·2015·CVSS 7.5
CVE-2015-2156 [HIGH] CVE-2015-2156: netty - Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final,...
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.
Scope: local
bookworm: resolved (fixed in 1:4.0.31-1)
bullseye: resolved (fixed in 1:4.0.31-1)
forky: resolved (fixed in 1:4.0.31-1)
sid: resolved (fixed in 1:4.0.31-1)
trixie: resolved (fixed in 1:4.0.31-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2156 netty: HttpOnly cookie bypass [fedora-all]
bugzilla·2015-05-19·CVSS 7.5
CVE-2015-2156 [HIGH] CVE-2015-2156 netty: HttpOnly cookie bypass [fedora-all]
CVE-2015-2156 netty: HttpOnly cookie bypass [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
on
Bugzilla
CVE-2015-2156 netty: HttpOnly cookie bypass
bugzilla·2015-05-19·CVSS 7.5
CVE-2015-2156 [HIGH] CVE-2015-2156 netty: HttpOnly cookie bypass
CVE-2015-2156 netty: HttpOnly cookie bypass
A flaw was found in the way Netty’s CookieDecoder method validated cookie name and value characters. An attacker could use this flaw to bypass the httpOnly flag on sensitive cookies.
Upstream patch:
https://github.com/slandelle/netty/commit/800555417e77029dcf8a31d7de44f27b5a8f79b8
External References:
https://www.playframework.com/security/vulnerability/CVE-2015-2156-HttpOnlyBypass
http://engineering.linkedin.com/security/look-netty%E2%80%99s-recent-security-update-cve%C2%AD-2015%C2%AD-2156
Discussion:
Created netty tracking bugs for this issue:
Affects: fedora-all [bug 1222927]
---
netty-4.0.28-1.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
---
netty-4.
http://lists.fedoraproject.org/pipermail/package-announce/2015-June/159379.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/159166.htmlhttp://netty.io/news/2015/05/08/3-9-8-Final-and-3.htmlhttp://www.openwall.com/lists/oss-security/2015/05/17/1http://www.securityfocus.com/bid/74704https://bugzilla.redhat.com/show_bug.cgi?id=1222923https://github.com/netty/netty/pull/3754https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/a19bb1003b0d6cd22475ba83c019b4fc7facfef2a9e13f71132529d3%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/dc1275aef115bda172851a231c76c0932d973f9ffd8bc375c4aba769%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3Ehttps://www.playframework.com/security/vulnerability/CVE-2015-2156-HttpOnlyBypasshttp://lists.fedoraproject.org/pipermail/package-announce/2015-June/159379.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2015-May/159166.htmlhttp://netty.io/news/2015/05/08/3-9-8-Final-and-3.htmlhttp://www.openwall.com/lists/oss-security/2015/05/17/1http://www.securityfocus.com/bid/74704https://bugzilla.redhat.com/show_bug.cgi?id=1222923https://github.com/netty/netty/pull/3754https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe%40%3Ccommits.druid.apache.org%3Ehttps://lists.apache.org/thread.html/a19bb1003b0d6cd22475ba83c019b4fc7facfef2a9e13f71132529d3%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/dc1275aef115bda172851a231c76c0932d973f9ffd8bc375c4aba769%40%3Ccommits.cassandra.apache.org%3Ehttps://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8%40%3Ccommits.pulsar.apache.org%3Ehttps://www.playframework.com/security/vulnerability/CVE-2015-2156-HttpOnlyBypass
2017-10-18
Published