Information Disclosure Vulnerability in Netty and Play Framework
CVE-2015-2156
7.5HIGH
Summary
The vulnerability in Netty and Play Framework allows remote attackers to potentially bypass the httpOnly flag on cookies. By exploiting improper validation of cookie name and value characters, attackers could gain access to sensitive information stored in cookies. This security flaw affects multiple versions of Netty as well as earlier versions of Play Framework, raising concerns about the secure handling of cookie data in applications leveraging these libraries.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved