7.5
CVE-2015-2156
- EPSS 0.43%
- Veröffentlicht 18.10.2017 15:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lightbend ≫ Play Framework Version2.0 Updaterc3
Lightbend ≫ Play Framework Version2.0 Updaterc4
Lightbend ≫ Play Framework Version2.0 Updaterc5
Lightbend ≫ Play Framework Version2.0.2
Lightbend ≫ Play Framework Version2.0.2 Updaterc1
Lightbend ≫ Play Framework Version2.0.2 Updaterc2
Lightbend ≫ Play Framework Version2.0.3
Lightbend ≫ Play Framework Version2.0.3 Updaterc1
Lightbend ≫ Play Framework Version2.0.3 Updaterc2
Lightbend ≫ Play Framework Version2.0.4
Lightbend ≫ Play Framework Version2.0.4 Updaterc1
Lightbend ≫ Play Framework Version2.0.4 Updaterc2
Lightbend ≫ Play Framework Version2.0.5
Lightbend ≫ Play Framework Version2.0.5 Updaterc1
Lightbend ≫ Play Framework Version2.0.5 Updaterc2
Lightbend ≫ Play Framework Version2.0.6
Lightbend ≫ Play Framework Version2.0.7
Lightbend ≫ Play Framework Version2.0.8
Lightbend ≫ Play Framework Version2.1.0
Lightbend ≫ Play Framework Version2.1.1
Lightbend ≫ Play Framework Version2.1.1 Updaterc1
Lightbend ≫ Play Framework Version2.2.0
Lightbend ≫ Play Framework Version2.2.1
Lightbend ≫ Play Framework Version2.2.2
Lightbend ≫ Play Framework Version2.2.6
Lightbend ≫ Play Framework Version2.3.0
Lightbend ≫ Play Framework Version2.3.0 Updaterc1
Lightbend ≫ Play Framework Version2.3.0 Updaterc2
Lightbend ≫ Play Framework Version2.3.1
Lightbend ≫ Play Framework Version2.3.2
Lightbend ≫ Play Framework Version2.3.2 Updaterc1
Lightbend ≫ Play Framework Version2.3.2 Updaterc2
Lightbend ≫ Play Framework Version2.3.3
Lightbend ≫ Play Framework Version2.3.4
Lightbend ≫ Play Framework Version2.3.5
Lightbend ≫ Play Framework Version2.3.6
Lightbend ≫ Play Framework Version2.3.7
Lightbend ≫ Play Framework Version2.3.8
Playframework ≫ Play Framework Version2.0
Playframework ≫ Play Framework Version2.0 Updatebeta
Playframework ≫ Play Framework Version2.0 Updaterc1
Playframework ≫ Play Framework Version2.0 Updaterc2
Playframework ≫ Play Framework Version2.0.1
Playframework ≫ Play Framework Version2.1.1 Update2.9.x-backport
Playframework ≫ Play Framework Version2.1.1 Updaterc1-2.9.x-backport
Playframework ≫ Play Framework Version2.1.1 Updaterc2
Playframework ≫ Play Framework Version2.1.2
Playframework ≫ Play Framework Version2.1.2 Updaterc1
Playframework ≫ Play Framework Version2.1.2 Updaterc2
Playframework ≫ Play Framework Version2.1.3
Playframework ≫ Play Framework Version2.1.3 Updaterc1
Playframework ≫ Play Framework Version2.1.3 Updaterc2
Playframework ≫ Play Framework Version2.1.4
Playframework ≫ Play Framework Version2.1.4 Updaterc1
Playframework ≫ Play Framework Version2.1.4 Updaterc2
Playframework ≫ Play Framework Version2.1.5
Playframework ≫ Play Framework Version2.1.6
Playframework ≫ Play Framework Version2.1.6 Updaterc1
Playframework ≫ Play Framework Version2.2.0 Updatem1
Playframework ≫ Play Framework Version2.2.0 Updatem2
Playframework ≫ Play Framework Version2.2.0 Updatem3
Playframework ≫ Play Framework Version2.2.0 Updaterc1
Playframework ≫ Play Framework Version2.2.0 Updaterc2
Playframework ≫ Play Framework Version2.2.1 Updaterc1
Playframework ≫ Play Framework Version2.2.2 Updaterc1
Playframework ≫ Play Framework Version2.2.2 Updaterc2
Playframework ≫ Play Framework Version2.2.2 Updaterc3
Playframework ≫ Play Framework Version2.2.2 Updaterc4
Playframework ≫ Play Framework Version2.2.3
Playframework ≫ Play Framework Version2.2.3 Updaterc1
Playframework ≫ Play Framework Version2.2.3 Updaterc2
Playframework ≫ Play Framework Version2.2.4
Playframework ≫ Play Framework Version2.2.5
Playframework ≫ Play Framework Version2.3 Updatem1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.43% | 0.616 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.