threat
engine
.sh
Back
·
··:··
Home
/
Product
/
lightbend play framework
Product
lightbend play framework
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2022-31023
< 2.8.16
Play Framework is a web framework for Java and Scala. Verions prior to 2.8.16 are vulnerable to generation of error messages conta
5.9
MEDIUM
CVE-2022-31018
>= 2.8.3 and <= 2.8.15
Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2.8.3 throu
7.5
HIGH
CVE-2020-28923
>= 2.8.0 and <= 2.8.4
An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data A
2.7
LOW
CVE-2020-27196
<= 2.6.25
An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly parses a payl
7.5
HIGH
CVE-2020-26883
<= 2.6.25
In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON d
7.5
HIGH
CVE-2020-26882
<= 2.6.25
In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.
7.5
HIGH
CVE-2020-12480
>= 2.6.0 and <= 2.6.25
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that cont
6.5
MEDIUM
CVE-2020-2200
<= 1.0.2
Jenkins Play Framework Plugin 1.0.2 and earlier lets users specify the path to the
play
command on the Jenkins master for a form
8.8
HIGH
CVE-2019-17598
>= 2.5.0 and <= 2.5.19
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated
7.5
HIGH
CVE-2018-13864
>= 2.6.12 and <= 2.6.15
A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.
7.5
HIGH
CVE-2014-3630
all versions
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might
9.8
CRITICAL
CVE-2015-2156
all versions
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2
7.5
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin