Lack of data validation In io.netty:netty-parent
Description
Information Exposure in Netty Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 4.0.2.8 | ||
maven | 3.9.8.final, 3.10.3.final | ||
maven | 3.10.3.final, 3.9.8.final | ||
maven | 4.0.28.final | ||
debian 14 | 1:4.0.31-1 | ||
debian 11 | 1:4.0.31-1 | ||
debian 13 | 1:4.0.31-1 | ||
debian 12 | 1:4.0.31-1 |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16.