Lightbend kayıtları
lightbend üreticisine ait 19 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %84,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-400 Uncontrolled Resource Consumption4
- CWE-674 Uncontrolled Recursion2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-326 Inadequate Encryption Strength1
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
19 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2014-3630İstismar yok | XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remlightbend · play framework · CWE-611 | Kritik9,8 | — | %2,9 | 29 Ara 2017 |
36İzleyin | CVE-2018-16115İstismar yok | Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error.lightbend · akka · CWE-338 | Kritik9,1 | — | %1,2 | 29 Ağu 2018 |
32İzleyin | CVE-2015-2156İstismar yok | Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before netty · netty · CWE-20 | Yüksek7,5 | — | %5,2 | 18 Eki 2017 |
31İzleyin | CVE-2018-13864Kavram kanıtı | A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when rlightbend · play framework · CWE-22 | Yüksek7,5 | — | %3,4 | 17 Tem 2018 |
31İzleyin | CVE-2018-16131İstismar yok | The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attalightbend · akka http · CWE-400 | Yüksek7,5 | — | %3,1 | 30 Ağu 2018 |
31İzleyin | CVE-2018-18853İstismar yok | Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic lightbend · spray-json · CWE-400 | Yüksek7,5 | — | %1,9 | 31 Eki 2018 |
31İzleyin | CVE-2018-18854İstismar yok | Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic lightbend · spray-json · CWE-400 | Yüksek7,5 | — | %1,9 | 31 Eki 2018 |
30İzleyin | CVE-2022-31018İstismar yok | Denial of service binding form from JSON in Play Frameworklightbend · play framework · CWE-400 | Yüksek7,5 | — | %1,7 | 2 Haz 2022 |
30İzleyin | CVE-2020-26882İstismar yok | In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.lightbend · play framework · CWE-674 | Yüksek7,5 | — | %1,4 | 6 Kas 2020 |
30İzleyin | CVE-2020-26883İstismar yok | In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.lightbend · play framework · CWE-674 | Yüksek7,5 | — | %1,4 | 6 Kas 2020 |
30İzleyin | CVE-2020-27196İstismar yok | An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2.lightbend · play framework · CWE-787 | Yüksek7,5 | — | %1,4 | 6 Kas 2020 |
30İzleyin | CVE-2022-31023İstismar yok | Dev error stack trace leaking into prod in Play Frameworklightbend · play framework · CWE-209 | Yüksek7,5 | — | %1,3 | 2 Haz 2022 |
30İzleyin | CVE-2019-17598İstismar yok | An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23.lightbend · play framework · CWE-326 | Yüksek7,5 | — | %0,7 | 5 Kas 2019 |
30İzleyin | CVE-2023-31442İstismar yok | In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictabllightbend · akka actor | Yüksek7,5 | — | %0,6 | 10 May 2023 |
26İzleyin | CVE-2021-23339İstismar yok | HTTP Request Smugglinglightbend · akka-http · CWE-444 | Orta6,5 | — | %0,7 | 17 Şub 2021 |
26İzleyin | CVE-2020-12480İstismar yok | In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain paramelightbend · play framework · CWE-352 | Orta6,5 | — | %0,5 | 17 Ağu 2020 |
22İzleyin | CVE-2023-29471İstismar yok | Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain clearlightbend · alpakka kafka · CWE-312 | Orta5,5 | — | %0,2 | 27 Nis 2023 |
22İzleyin | CVE-2023-33251İstismar yok | When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has tolightbend · akka http · CWE-732 | Orta5,5 | — | %0,2 | 21 May 2023 |
10İzleyin | CVE-2020-28923İstismar yok | An issue was discovered in Play Framework 2.8.0 through 2.8.4.lightbend · play framework | Düşük2,7 | — | %1,0 | 3 Ara 2020 |
- CVE-2014-363040Planlayın
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow rem
KritikCVSS 9,8İstismar yokEPSS %3lightbend · play framework29 Ara 2017
- CVE-2018-1611536İzleyin
Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error.
KritikCVSS 9,1İstismar yokEPSS %1lightbend · akka29 Ağu 2018
- CVE-2015-215632İzleyin
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before
YüksekCVSS 7,5İstismar yokEPSS %5netty · netty18 Eki 2017
- CVE-2018-1386431İzleyin
A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when r
YüksekCVSS 7,5Kavram kanıtıEPSS %3lightbend · play framework17 Tem 2018
- CVE-2018-1613131İzleyin
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote atta
YüksekCVSS 7,5İstismar yokEPSS %3lightbend · akka http30 Ağu 2018
- CVE-2018-1885331İzleyin
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic
YüksekCVSS 7,5İstismar yokEPSS %2lightbend · spray-json31 Eki 2018
- CVE-2018-1885431İzleyin
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic
YüksekCVSS 7,5İstismar yokEPSS %2lightbend · spray-json31 Eki 2018
- CVE-2022-3101830İzleyin
Denial of service binding form from JSON in Play Framework
YüksekCVSS 7,5İstismar yokEPSS %2lightbend · play framework2 Haz 2022
- CVE-2020-2688230İzleyin
In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.
YüksekCVSS 7,5İstismar yokEPSS %1lightbend · play framework6 Kas 2020
- CVE-2020-2688330İzleyin
In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.
YüksekCVSS 7,5İstismar yokEPSS %1lightbend · play framework6 Kas 2020
- CVE-2020-2719630İzleyin
An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2.
YüksekCVSS 7,5İstismar yokEPSS %1lightbend · play framework6 Kas 2020
- CVE-2022-3102330İzleyin
Dev error stack trace leaking into prod in Play Framework
YüksekCVSS 7,5İstismar yokEPSS %1lightbend · play framework2 Haz 2022
- CVE-2019-1759830İzleyin
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23.
YüksekCVSS 7,5İstismar yokEPSS %1lightbend · play framework5 Kas 2019
- CVE-2023-3144230İzleyin
In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictabl
YüksekCVSS 7,5İstismar yokEPSS %1lightbend · akka actor10 May 2023
- CVE-2021-2333926İzleyin
HTTP Request Smuggling
OrtaCVSS 6,5İstismar yokEPSS %1lightbend · akka-http17 Şub 2021
- CVE-2020-1248026İzleyin
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parame
OrtaCVSS 6,5İstismar yokEPSS %1lightbend · play framework17 Ağu 2020
- CVE-2023-2947122İzleyin
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain clear
OrtaCVSS 5,5İstismar yokEPSS %0lightbend · alpakka kafka27 Nis 2023
- CVE-2023-3325122İzleyin
When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has to
OrtaCVSS 5,5İstismar yokEPSS %0lightbend · akka http21 May 2023
- CVE-2020-2892310İzleyin
An issue was discovered in Play Framework 2.8.0 through 2.8.4.
DüşükCVSS 2,7İstismar yokEPSS %1lightbend · play framework3 Ara 2020