Записи Lightbend
19 опубликованных записей вендора lightbend.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 84,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-400 Uncontrolled Resource Consumption4
- CWE-674 Uncontrolled Recursion2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-312 Cleartext Storage of Sensitive Information1
- CWE-326 Inadequate Encryption Strength1
- CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
19 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2014-3630Эксплойта нет | XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remlightbend · play framework · CWE-611 | Критическая9,8 | — | 2,9 % | 29 дек. 2017 г. |
36Наблюдать | CVE-2018-16115Эксплойта нет | Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error.lightbend · akka · CWE-338 | Критическая9,1 | — | 1,2 % | 29 авг. 2018 г. |
32Наблюдать | CVE-2015-2156Эксплойта нет | Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before netty · netty · CWE-20 | Высокая7,5 | — | 5,2 % | 18 окт. 2017 г. |
31Наблюдать | CVE-2018-13864Proof of concept | A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when rlightbend · play framework · CWE-22 | Высокая7,5 | — | 3,4 % | 17 июл. 2018 г. |
31Наблюдать | CVE-2018-16131Эксплойта нет | The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote attalightbend · akka http · CWE-400 | Высокая7,5 | — | 3,1 % | 30 авг. 2018 г. |
31Наблюдать | CVE-2018-18853Эксплойта нет | Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic lightbend · spray-json · CWE-400 | Высокая7,5 | — | 1,9 % | 31 окт. 2018 г. |
31Наблюдать | CVE-2018-18854Эксплойта нет | Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic lightbend · spray-json · CWE-400 | Высокая7,5 | — | 1,9 % | 31 окт. 2018 г. |
30Наблюдать | CVE-2022-31018Эксплойта нет | Denial of service binding form from JSON in Play Frameworklightbend · play framework · CWE-400 | Высокая7,5 | — | 1,7 % | 2 июн. 2022 г. |
30Наблюдать | CVE-2020-26882Эксплойта нет | In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.lightbend · play framework · CWE-674 | Высокая7,5 | — | 1,4 % | 6 нояб. 2020 г. |
30Наблюдать | CVE-2020-26883Эксплойта нет | In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.lightbend · play framework · CWE-674 | Высокая7,5 | — | 1,4 % | 6 нояб. 2020 г. |
30Наблюдать | CVE-2020-27196Эксплойта нет | An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2.lightbend · play framework · CWE-787 | Высокая7,5 | — | 1,4 % | 6 нояб. 2020 г. |
30Наблюдать | CVE-2022-31023Эксплойта нет | Dev error stack trace leaking into prod in Play Frameworklightbend · play framework · CWE-209 | Высокая7,5 | — | 1,3 % | 2 июн. 2022 г. |
30Наблюдать | CVE-2019-17598Эксплойта нет | An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23.lightbend · play framework · CWE-326 | Высокая7,5 | — | 0,7 % | 5 нояб. 2019 г. |
30Наблюдать | CVE-2023-31442Эксплойта нет | In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictabllightbend · akka actor | Высокая7,5 | — | 0,6 % | 10 мая 2023 г. |
26Наблюдать | CVE-2021-23339Эксплойта нет | HTTP Request Smugglinglightbend · akka-http · CWE-444 | Средняя6,5 | — | 0,7 % | 17 февр. 2021 г. |
26Наблюдать | CVE-2020-12480Эксплойта нет | In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain paramelightbend · play framework · CWE-352 | Средняя6,5 | — | 0,5 % | 17 авг. 2020 г. |
22Наблюдать | CVE-2023-29471Эксплойта нет | Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain clearlightbend · alpakka kafka · CWE-312 | Средняя5,5 | — | 0,2 % | 27 апр. 2023 г. |
22Наблюдать | CVE-2023-33251Эксплойта нет | When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has tolightbend · akka http · CWE-732 | Средняя5,5 | — | 0,2 % | 21 мая 2023 г. |
10Наблюдать | CVE-2020-28923Эксплойта нет | An issue was discovered in Play Framework 2.8.0 through 2.8.4.lightbend · play framework | Низкая2,7 | — | 1,0 % | 3 дек. 2020 г. |
- CVE-2014-363040В плане
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow rem
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %lightbend · play framework29 дек. 2017 г.
- CVE-2018-1611536Наблюдать
Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %lightbend · akka29 авг. 2018 г.
- CVE-2015-215632Наблюдать
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %netty · netty18 окт. 2017 г.
- CVE-2018-1386431Наблюдать
A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when r
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %lightbend · play framework17 июл. 2018 г.
- CVE-2018-1613131Наблюдать
The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote atta
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %lightbend · akka http30 авг. 2018 г.
- CVE-2018-1885331Наблюдать
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %lightbend · spray-json31 окт. 2018 г.
- CVE-2018-1885431Наблюдать
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %lightbend · spray-json31 окт. 2018 г.
- CVE-2022-3101830Наблюдать
Denial of service binding form from JSON in Play Framework
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %lightbend · play framework2 июн. 2022 г.
- CVE-2020-2688230Наблюдать
In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %lightbend · play framework6 нояб. 2020 г.
- CVE-2020-2688330Наблюдать
In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %lightbend · play framework6 нояб. 2020 г.
- CVE-2020-2719630Наблюдать
An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %lightbend · play framework6 нояб. 2020 г.
- CVE-2022-3102330Наблюдать
Dev error stack trace leaking into prod in Play Framework
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %lightbend · play framework2 июн. 2022 г.
- CVE-2019-1759830Наблюдать
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %lightbend · play framework5 нояб. 2019 г.
- CVE-2023-3144230Наблюдать
In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictabl
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %lightbend · akka actor10 мая 2023 г.
- CVE-2021-2333926Наблюдать
HTTP Request Smuggling
СредняяCVSS 6,5Эксплойта нетEPSS 1 %lightbend · akka-http17 февр. 2021 г.
- CVE-2020-1248026Наблюдать
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parame
СредняяCVSS 6,5Эксплойта нетEPSS 1 %lightbend · play framework17 авг. 2020 г.
- CVE-2023-2947122Наблюдать
Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain clear
СредняяCVSS 5,5Эксплойта нетEPSS 0 %lightbend · alpakka kafka27 апр. 2023 г.
- CVE-2023-3325122Наблюдать
When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has to
СредняяCVSS 5,5Эксплойта нетEPSS 0 %lightbend · akka http21 мая 2023 г.
- CVE-2020-2892310Наблюдать
An issue was discovered in Play Framework 2.8.0 through 2.8.4.
НизкаяCVSS 2,7Эксплойта нетEPSS 1 %lightbend · play framework3 дек. 2020 г.