PT-2017-5880 · Lightbend · Play

David Jorm

·

Publicado

2017-12-29

·

Atualizado

2019-11-25

·

CVE-2014-3630

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Play versions prior to 2.2.6 Play versions 2.3.x prior to 2.3.5
Description: The issue is related to an XML external entity (XXE) vulnerability in the Java XML processing functionality. This might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
Recommendations: For Play versions prior to 2.2.6, update to version 2.2.6 or later. For Play versions 2.3.x prior to 2.3.5, update to version 2.3.5 or later.

Correção

DoS

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-3630

Produtos afetados

Play