CVE-2015-2156

high
Published 2017-10-18 · Modified 2026-04-10
CVSS v3
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
VIR risk
7.5

Description

Information Exposure in Netty

Predictions

Exploit likelihood
83%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed1:4.0.31-1
debian debianbullseyefixed1:4.0.31-1
debian debianforkyfixed1:4.0.31-1
debian debiansidfixed1:4.0.31-1
debian debiantrixiefixed1:4.0.31-1

Package impact

EcosystemPackageVulnerableFixed
java Mavenio.netty:netty-parent>=4.0.0,<4.0.28.Final4.0.28.Final
java Mavenorg.jboss.netty:netty<3.9.8.Final3.9.8.Final
java Mavenorg.jboss.netty:netty>=3.10.0,<3.10.3.Final3.10.3.Final
java Mavenio.netty:netty>=3.10.0,<3.10.3.Final3.10.3.Final
java Mavenio.netty:netty<3.9.8.Final3.9.8.Final

Application impact

VendorProductVersionsFixed
nettynetty{"endIncluding":"3.9.7"}
nettynetty3.10.0
nettynetty3.10.1
nettynetty3.10.2
nettynetty4.0.0
nettynetty4.0.1
nettynetty4.0.2
nettynetty4.0.3
nettynetty4.0.4
nettynetty4.0.5
nettynetty4.0.6
nettynetty4.0.7
nettynetty4.0.8
nettynetty4.0.9
nettynetty4.0.10
nettynetty4.0.11
nettynetty4.0.12
nettynetty4.0.13
nettynetty4.0.14
nettynetty4.0.15
nettynetty4.0.16
nettynetty4.0.17
nettynetty4.0.18
nettynetty4.0.19
nettynetty4.0.20
nettynetty4.0.21
nettynetty4.0.22
nettynetty4.0.23
nettynetty4.0.24
nettynetty4.0.25
nettynetty4.0.26
nettynetty4.0.27
nettynetty4.1.0
lightbendplay_framework2.0
lightbendplay_framework2.0.2
lightbendplay_framework2.0.3
lightbendplay_framework2.0.4
lightbendplay_framework2.0.5
lightbendplay_framework2.0.6
lightbendplay_framework2.0.7
lightbendplay_framework2.0.8
lightbendplay_framework2.1.0
lightbendplay_framework2.1.1
lightbendplay_framework2.2.0
lightbendplay_framework2.2.1
lightbendplay_framework2.2.2
lightbendplay_framework2.2.6
lightbendplay_framework2.3.0
lightbendplay_framework2.3.1
lightbendplay_framework2.3.2
lightbendplay_framework2.3.3
lightbendplay_framework2.3.4
lightbendplay_framework2.3.5
lightbendplay_framework2.3.6
lightbendplay_framework2.3.7
lightbendplay_framework2.3.8
playframeworkplay_framework2.0
playframeworkplay_framework2.0.1
playframeworkplay_framework2.1.1
playframeworkplay_framework2.1.2
playframeworkplay_framework2.1.3
playframeworkplay_framework2.1.4
playframeworkplay_framework2.1.5
playframeworkplay_framework2.1.6
playframeworkplay_framework2.2.0
playframeworkplay_framework2.2.1
playframeworkplay_framework2.2.2
playframeworkplay_framework2.2.3
playframeworkplay_framework2.2.4
playframeworkplay_framework2.2.5
playframeworkplay_framework2.3

References

CWEs

CWE-20

💬 Discuss CVE-2015-2156 on VIR Community →

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.