CVE-2015-2156

Source
https://nvd.nist.gov/vuln/detail/CVE-2015-2156
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2015-2156.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2015-2156
Aliases
Downstream
Published
2017-10-18T15:29:00Z
Modified
2025-08-09T20:01:26Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.

References

Affected packages