Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
lightbend vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2018-18854
Lightbend Spray spray-json up to and including 1.3.4 allows remote malicious users to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of many JSON object fields (with keys that have the same hash code).
Lightbend Spray-json
7.5
CVSSv3
CVE-2022-31018
Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2.8.3 up to and including 2.8.15 of Play's forms library, in both the Scala and Java APIs. This can occur when using either the `Form#bindFromRequest` metho...
Lightbend Play Framework
7.5
CVSSv3
CVE-2018-16131
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x up to and including 10.1.4 and 10.0.x up to and including 10.0.13 allow remote malicious users to cause a denial of service (memory consumption and daemon crash) via a ZIP bomb.
Lightbend Akka Http
5.5
CVSSv3
CVE-2023-29471
Lightbend Alpakka Kafka prior to 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor.
Lightbend Alpakka Kafka
2.7
CVSSv3
CVE-2020-28923
An issue exists in Play Framework 2.8.0 up to and including 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data Amplification. This affects users migrating from a Play version before 2.8.0 that used the Play Java API to serialize classes with protected or pri...
Lightbend Play Framework
7.5
CVSSv3
CVE-2020-26882
In Play Framework 2.6.0 up to and including 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.
Lightbend Play Framework
7.5
CVSSv3
CVE-2019-17598
An issue exists in Lightbend Play Framework 2.5.x up to and including 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the ta...
Lightbend Play Framework
7.5
CVSSv3
CVE-2020-26883
In Play Framework 2.6.0 up to and including 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.
Lightbend Play Framework
7.5
CVSSv3
CVE-2022-31023
Play Framework is a web framework for Java and Scala. Verions before 2.8.16 are vulnerable to generation of error messages containing sensitive information. Play Framework, when run in dev mode, shows verbose errors for easy debugging, including an exception stack trace. Play doe...
Lightbend Play Framework
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-26925
CVE-2023-41826
LFI
CVE-2022-22364
CVE-2024-2887
command injection
remote code execution
CVE-2024-34446
CVE-2022-48699
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2