Lightbend records
19 published records for vendor lightbend.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 84.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption4
- CWE-674 Uncontrolled Recursion2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-326 Inadequate Encryption Strength1
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2014-3630No exploit | XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remlightbend · play framework · CWE-611 | Critical9.8 | — | 2.9% | Dec 29, 2017 |
36Monitor | CVE-2018-16115No exploit | Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error.lightbend · akka · CWE-338 | Critical9.1 | — | 1.2% | Aug 29, 2018 |
32Monitor | CVE-2015-2156No exploit | Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before netty · netty · CWE-20 | High7.5 | — | 5.2% | Oct 18, 2017 |
31Monitor | CVE-2018-13864Proof of concept | A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when rlightbend · play framework · CWE-22 | High7.5 | — | 3.4% | Jul 17, 2018 |
31Monitor | CVE-2018-16131No exploit | The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attalightbend · akka http · CWE-400 | High7.5 | — | 3.1% | Aug 30, 2018 |
31Monitor | CVE-2018-18853No exploit | Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic lightbend · spray-json · CWE-400 | High7.5 | — | 1.9% | Oct 31, 2018 |
31Monitor | CVE-2018-18854No exploit | Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic lightbend · spray-json · CWE-400 | High7.5 | — | 1.9% | Oct 31, 2018 |
30Monitor | CVE-2022-31018No exploit | Denial of service binding form from JSON in Play Frameworklightbend · play framework · CWE-400 | High7.5 | — | 1.7% | Jun 2, 2022 |
30Monitor | CVE-2020-26882No exploit | In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.lightbend · play framework · CWE-674 | High7.5 | — | 1.4% | Nov 6, 2020 |
30Monitor | CVE-2020-26883No exploit | In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.lightbend · play framework · CWE-674 | High7.5 | — | 1.4% | Nov 6, 2020 |
30Monitor | CVE-2020-27196No exploit | An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2.lightbend · play framework · CWE-787 | High7.5 | — | 1.4% | Nov 6, 2020 |
30Monitor | CVE-2022-31023No exploit | Dev error stack trace leaking into prod in Play Frameworklightbend · play framework · CWE-209 | High7.5 | — | 1.3% | Jun 2, 2022 |
30Monitor | CVE-2019-17598No exploit | An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23.lightbend · play framework · CWE-326 | High7.5 | — | 0.7% | Nov 5, 2019 |
30Monitor | CVE-2023-31442No exploit | In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictabllightbend · akka actor | High7.5 | — | 0.6% | May 10, 2023 |
26Monitor | CVE-2021-23339No exploit | HTTP Request Smugglinglightbend · akka-http · CWE-444 | Medium6.5 | — | 0.7% | Feb 17, 2021 |
26Monitor | CVE-2020-12480No exploit | In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain paramelightbend · play framework · CWE-352 | Medium6.5 | — | 0.5% | Aug 17, 2020 |
22Monitor | CVE-2023-29471No exploit | Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain clearlightbend · alpakka kafka · CWE-312 | Medium5.5 | — | 0.2% | Apr 27, 2023 |
22Monitor | CVE-2023-33251No exploit | When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has tolightbend · akka http · CWE-732 | Medium5.5 | — | 0.2% | May 21, 2023 |
10Monitor | CVE-2020-28923No exploit | An issue was discovered in Play Framework 2.8.0 through 2.8.4.lightbend · play framework | Low2.7 | — | 1.0% | Dec 3, 2020 |
- CVE-2014-363040Plan
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow rem
CriticalCVSS 9.8No exploitEPSS 3%lightbend · play frameworkDec 29, 2017
- CVE-2018-1611536Monitor
Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error.
CriticalCVSS 9.1No exploitEPSS 1%lightbend · akkaAug 29, 2018
- CVE-2015-215632Monitor
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before
HighCVSS 7.5No exploitEPSS 5%netty · nettyOct 18, 2017
- CVE-2018-1386431Monitor
A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when r
HighCVSS 7.5Proof of conceptEPSS 3%lightbend · play frameworkJul 17, 2018
- CVE-2018-1613131Monitor
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote atta
HighCVSS 7.5No exploitEPSS 3%lightbend · akka httpAug 30, 2018
- CVE-2018-1885331Monitor
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic
HighCVSS 7.5No exploitEPSS 2%lightbend · spray-jsonOct 31, 2018
- CVE-2018-1885431Monitor
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic
HighCVSS 7.5No exploitEPSS 2%lightbend · spray-jsonOct 31, 2018
- CVE-2022-3101830Monitor
Denial of service binding form from JSON in Play Framework
HighCVSS 7.5No exploitEPSS 2%lightbend · play frameworkJun 2, 2022
- CVE-2020-2688230Monitor
In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.
HighCVSS 7.5No exploitEPSS 1%lightbend · play frameworkNov 6, 2020
- CVE-2020-2688330Monitor
In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.
HighCVSS 7.5No exploitEPSS 1%lightbend · play frameworkNov 6, 2020
- CVE-2020-2719630Monitor
An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2.
HighCVSS 7.5No exploitEPSS 1%lightbend · play frameworkNov 6, 2020
- CVE-2022-3102330Monitor
Dev error stack trace leaking into prod in Play Framework
HighCVSS 7.5No exploitEPSS 1%lightbend · play frameworkJun 2, 2022
- CVE-2019-1759830Monitor
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23.
HighCVSS 7.5No exploitEPSS 1%lightbend · play frameworkNov 5, 2019
- CVE-2023-3144230Monitor
In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictabl
HighCVSS 7.5No exploitEPSS 1%lightbend · akka actorMay 10, 2023
- CVE-2021-2333926Monitor
HTTP Request Smuggling
MediumCVSS 6.5No exploitEPSS 1%lightbend · akka-httpFeb 17, 2021
- CVE-2020-1248026Monitor
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parame
MediumCVSS 6.5No exploitEPSS 1%lightbend · play frameworkAug 17, 2020
- CVE-2023-2947122Monitor
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain clear
MediumCVSS 5.5No exploitEPSS 0%lightbend · alpakka kafkaApr 27, 2023
- CVE-2023-3325122Monitor
When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has to
MediumCVSS 5.5No exploitEPSS 0%lightbend · akka httpMay 21, 2023
- CVE-2020-2892310Monitor
An issue was discovered in Play Framework 2.8.0 through 2.8.4.
LowCVSS 2.7No exploitEPSS 1%lightbend · play frameworkDec 3, 2020