Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
lightbend vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2023-31442
In Lightbend Akka prior to 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictable DNS transaction IDs when resolving DNS records, making DNS resolution subject to poisoning by an attacker. If the application performing...
Lightbend Akka Discovery
Lightbend Akka Actor
9.8
CVSSv3
CVE-2014-3630
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play prior to 2.2.6 and 2.3.x prior to 2.3.5 might allow remote malicious users to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
Playframework Play Framework 2.2.5
Playframework Play Framework 2.2.4
Playframework Play Framework 2.2.3
Playframework Play Framework 2.2.2
Playframework Play Framework 2.2.1
Playframework Play Framework 2.2.0
Lightbend Play Framework 2.2.0
Lightbend Play Framework 2.2.1
Lightbend Play Framework 2.2.2
Lightbend Play Framework 2.3.0
Lightbend Play Framework 2.3.1
Lightbend Play Framework 2.3.2
Lightbend Play Framework 2.3.3
Lightbend Play Framework 2.3.4
7.5
CVSSv3
CVE-2015-2156
Netty prior to 3.9.8.Final, 3.10.x prior to 3.10.3.Final, 4.0.x prior to 4.0.28.Final, and 4.1.x prior to 4.1.0.Beta5 and Play Framework 2.x prior to 2.3.9 might allow remote malicious users to bypass the httpOnly flag on cookies and obtain sensitive information by leveraging imp...
Netty Netty 4.0.16
Netty Netty 4.0.17
Netty Netty 4.0.18
Netty Netty 4.0.19
Netty Netty 4.0.20
Netty Netty 4.0.21
Netty Netty 4.0.22
Netty Netty 4.0.23
Netty Netty 4.0.24
Netty Netty 4.0.25
Netty Netty 4.0.26
Netty Netty 4.0.27
Netty Netty
Netty Netty 3.10.0
Netty Netty 3.10.1
Netty Netty 3.10.2
Netty Netty 4.0.1
Netty Netty 4.0.2
Netty Netty 4.0.3
Netty Netty 4.0.4
Netty Netty 4.0.5
Netty Netty 4.0.6
5.5
CVSSv3
CVE-2023-33251
When Akka HTTP prior to 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has too weak permissions: it is readable by other users on Linux or UNIX, a similar issue to CVE-2022-41946.
Lightbend Akka Http
7.5
CVSSv3
CVE-2018-13864
A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 up to and including 2.6.15 (fixed in 2.6.16) when running on Windows. It allows a remote malicious user to download arbitrary files from the target server via specially crafted HT...
Lightbend Play Framework
9.1
CVSSv3
CVE-2018-16115
Lightbend Akka 2.5.x prior to 2.5.16 allows message disclosure and modification because of an RNG error. A random number generator is used in Akka Remoting for TLS (both classic and Artery Remoting). Akka allows configuration of custom random number generators. For historical rea...
Lightbend Akka
7.5
CVSSv3
CVE-2019-17598
An issue exists in Lightbend Play Framework 2.5.x up to and including 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the ta...
Lightbend Play Framework
7.5
CVSSv3
CVE-2022-31018
Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2.8.3 up to and including 2.8.15 of Play's forms library, in both the Scala and Java APIs. This can occur when using either the `Form#bindFromRequest` metho...
Lightbend Play Framework
7.5
CVSSv3
CVE-2022-31023
Play Framework is a web framework for Java and Scala. Verions before 2.8.16 are vulnerable to generation of error messages containing sensitive information. Play Framework, when run in dev mode, shows verbose errors for easy debugging, including an exception stack trace. Play doe...
Lightbend Play Framework
7.5
CVSSv3
CVE-2018-18853
Lightbend Spray spray-json up to and including 1.3.4 allows remote malicious users to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of a field composed of many decimal digits.
Lightbend Spray-json
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3400
CVE-2023-7252
CVE-2024-21111
denial of service
CVE-2024-29661
CVE-2024-22856
remote attackers
encryption
CVE-2023-38299
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »