QID 980761

QID 980761: Java (maven) Security Update for io.netty:netty-handler (GHSA-xfv3-rrfm-f2rv)

Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging improper validation of cookie name and value characters.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-xfv3-rrfm-f2rv for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 980761

    Software Advisories
    Advisory ID Software Component Link
    GHSA-xfv3-rrfm-f2rv io.netty:netty-handler URL Logo github.com/advisories/GHSA-xfv3-rrfm-f2rv