PT-2020-16529 · Lightbend · Play Framework
Lucash-Dev
·
Published
2020-11-06
·
Updated
2022-02-10
·
CVE-2020-26883
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Play Framework versions 2.6.0 through 2.8.2
Description
The issue is caused by unbounded recursion during parsing of crafted JSON documents, leading to stack consumption.
Recommendations
For Play Framework versions 2.6.0 through 2.8.2, update to a version that contains a fix for this issue to prevent stack consumption due to unbounded recursion during JSON parsing.
Fix
Uncontrolled Recursion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Play Framework