Skip to content
Noroxi

Lightbend records

19 published records for vendor lightbend.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
84.2%
Median publish → KEV
No record has entered KEV

All records

19 records
  • XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow rem

    CriticalCVSS 9.8No exploitEPSS 3%

    lightbend · play frameworkDec 29, 2017

  • Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error.

    CriticalCVSS 9.1No exploitEPSS 1%

    lightbend · akkaAug 29, 2018

  • CVE-2015-2156
    32Monitor

    Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before

    HighCVSS 7.5No exploitEPSS 5%

    netty · nettyOct 18, 2017

  • A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when r

    HighCVSS 7.5Proof of conceptEPSS 3%

    lightbend · play frameworkJul 17, 2018

  • The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote atta

    HighCVSS 7.5No exploitEPSS 3%

    lightbend · akka httpAug 30, 2018

  • Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic

    HighCVSS 7.5No exploitEPSS 2%

    lightbend · spray-jsonOct 31, 2018

  • Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic

    HighCVSS 7.5No exploitEPSS 2%

    lightbend · spray-jsonOct 31, 2018

  • Denial of service binding form from JSON in Play Framework

    HighCVSS 7.5No exploitEPSS 2%

    lightbend · play frameworkJun 2, 2022

  • In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.

    HighCVSS 7.5No exploitEPSS 1%

    lightbend · play frameworkNov 6, 2020

  • In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.

    HighCVSS 7.5No exploitEPSS 1%

    lightbend · play frameworkNov 6, 2020

  • An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2.

    HighCVSS 7.5No exploitEPSS 1%

    lightbend · play frameworkNov 6, 2020

  • Dev error stack trace leaking into prod in Play Framework

    HighCVSS 7.5No exploitEPSS 1%

    lightbend · play frameworkJun 2, 2022

  • An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23.

    HighCVSS 7.5No exploitEPSS 1%

    lightbend · play frameworkNov 5, 2019

  • In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictabl

    HighCVSS 7.5No exploitEPSS 1%

    lightbend · akka actorMay 10, 2023

  • HTTP Request Smuggling

    MediumCVSS 6.5No exploitEPSS 1%

    lightbend · akka-httpFeb 17, 2021

  • In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parame

    MediumCVSS 6.5No exploitEPSS 1%

    lightbend · play frameworkAug 17, 2020

  • Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain clear

    MediumCVSS 5.5No exploitEPSS 0%

    lightbend · alpakka kafkaApr 27, 2023

  • When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has to

    MediumCVSS 5.5No exploitEPSS 0%

    lightbend · akka httpMay 21, 2023

  • An issue was discovered in Play Framework 2.8.0 through 2.8.4.

    LowCVSS 2.7No exploitEPSS 1%

    lightbend · play frameworkDec 3, 2020