Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
lightbend play framework vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2022-31023
Play Framework is a web framework for Java and Scala. Verions before 2.8.16 are vulnerable to generation of error messages containing sensitive information. Play Framework, when run in dev mode, shows verbose errors for easy debugging, including an exception stack trace. Play doe...
Lightbend Play Framework
5
CVSSv2
CVE-2022-31018
Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2.8.3 up to and including 2.8.15 of Play's forms library, in both the Scala and Java APIs. This can occur when using either the `Form#bindFromRequest` metho...
Lightbend Play Framework
4
CVSSv2
CVE-2020-28923
An issue exists in Play Framework 2.8.0 up to and including 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data Amplification. This affects users migrating from a Play version before 2.8.0 that used the Play Java API to serialize classes with protected or pri...
Lightbend Play Framework
5
CVSSv2
CVE-2020-27196
An issue exists in PlayJava in Play Framework 2.6.0 up to and including 2.8.2. The body parsing of HTTP requests eagerly parses a payload given a Content-Type header. A deep JSON structure sent to a valid POST endpoint (that may or may not expect JSON payloads) causes a StackOver...
Lightbend Play Framework
5
CVSSv2
CVE-2020-26882
In Play Framework 2.6.0 up to and including 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.
Lightbend Play Framework
5
CVSSv2
CVE-2020-26883
In Play Framework 2.6.0 up to and including 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.
Lightbend Play Framework
4.3
CVSSv2
CVE-2020-12480
In Play Framework 2.6.0 up to and including 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Lightbend Play Framework
4.3
CVSSv2
CVE-2019-17598
An issue exists in Lightbend Play Framework 2.5.x up to and including 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the ta...
Lightbend Play Framework
5
CVSSv2
CVE-2018-13864
A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 up to and including 2.6.15 (fixed in 2.6.16) when running on Windows. It allows a remote malicious user to download arbitrary files from the target server via specially crafted HT...
Lightbend Play Framework
7.5
CVSSv2
CVE-2014-3630
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play prior to 2.2.6 and 2.3.x prior to 2.3.5 might allow remote malicious users to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
Playframework Play Framework 2.2.5
Playframework Play Framework 2.2.4
Playframework Play Framework 2.2.3
Playframework Play Framework 2.2.2
Playframework Play Framework 2.2.1
Playframework Play Framework 2.2.0
Lightbend Play Framework 2.2.0
Lightbend Play Framework 2.2.1
Lightbend Play Framework 2.2.2
Lightbend Play Framework 2.3.0
Lightbend Play Framework 2.3.1
Lightbend Play Framework 2.3.2
Lightbend Play Framework 2.3.3
Lightbend Play Framework 2.3.4
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48700
CVE-2022-48689
CVE-2024-27956
CVE-2023-6363
SQL
NULL pointer dereference
CVE-2023-41830
CVE-2015-2051
arbitrary
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »