VDB
Sign up
HIGH7.5

GHSA-xfv3-rrfm-f2rv

Information Exposure in Netty

Quick fix

GHSA-xfv3-rrfm-f2rv — io.netty:netty-parent: upgrade to the fixed version with the command below.

# pom.xml: bump <version>4.0.28.Final</version> for io.netty:netty-parent

Details

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/io.netty:netty-parent
Introduced in: 4.0.0Fixed in: 4.0.28.Final
Fix# pom.xml: bump <version>4.0.28.Final</version> for io.netty:netty-parent
Maven/org.jboss.netty:netty
Introduced in: 0Fixed in: 3.9.8.Final
Fix# pom.xml: bump <version>3.9.8.Final</version> for org.jboss.netty:netty
Maven/org.jboss.netty:netty
Introduced in: 3.10.0Fixed in: 3.10.3.Final
Fix# pom.xml: bump <version>3.10.3.Final</version> for org.jboss.netty:netty
Maven/io.netty:netty
Introduced in: 3.10.0Fixed in: 3.10.3.Final
Fix# pom.xml: bump <version>3.10.3.Final</version> for io.netty:netty
Maven/io.netty:netty
Introduced in: 0Fixed in: 3.9.8.Final
Fix# pom.xml: bump <version>3.9.8.Final</version> for io.netty:netty

References