İçeriğe atla
Noroxi

Lightbend kayıtları

lightbend üreticisine ait 19 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%84,2
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

19 kayıt
  • CVE-2014-3630
    40Planlayın

    XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow rem

    KritikCVSS 9,8İstismar yokEPSS %3

    lightbend · play framework29 Ara 2017

  • CVE-2018-16115
    36İzleyin

    Lightbend Akka 2.5.x before 2.5.16 allows message disclosure and modification because of an RNG error.

    KritikCVSS 9,1İstismar yokEPSS %1

    lightbend · akka29 Ağu 2018

  • CVE-2015-2156
    32İzleyin

    Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before

    YüksekCVSS 7,5İstismar yokEPSS %5

    netty · netty18 Eki 2017

  • CVE-2018-13864
    31İzleyin

    A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when r

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    lightbend · play framework17 Tem 2018

  • CVE-2018-16131
    31İzleyin

    The decodeRequest and decodeRequestWith directives in Lightbend Akka HTTP 10.1.x through 10.1.4 and 10.0.x through 10.0.13 allow remote atta

    YüksekCVSS 7,5İstismar yokEPSS %3

    lightbend · akka http30 Ağu 2018

  • CVE-2018-18853
    31İzleyin

    Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic

    YüksekCVSS 7,5İstismar yokEPSS %2

    lightbend · spray-json31 Eki 2018

  • CVE-2018-18854
    31İzleyin

    Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic

    YüksekCVSS 7,5İstismar yokEPSS %2

    lightbend · spray-json31 Eki 2018

  • CVE-2022-31018
    30İzleyin

    Denial of service binding form from JSON in Play Framework

    YüksekCVSS 7,5İstismar yokEPSS %2

    lightbend · play framework2 Haz 2022

  • CVE-2020-26882
    30İzleyin

    In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.

    YüksekCVSS 7,5İstismar yokEPSS %1

    lightbend · play framework6 Kas 2020

  • CVE-2020-26883
    30İzleyin

    In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.

    YüksekCVSS 7,5İstismar yokEPSS %1

    lightbend · play framework6 Kas 2020

  • CVE-2020-27196
    30İzleyin

    An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2.

    YüksekCVSS 7,5İstismar yokEPSS %1

    lightbend · play framework6 Kas 2020

  • CVE-2022-31023
    30İzleyin

    Dev error stack trace leaking into prod in Play Framework

    YüksekCVSS 7,5İstismar yokEPSS %1

    lightbend · play framework2 Haz 2022

  • CVE-2019-17598
    30İzleyin

    An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23.

    YüksekCVSS 7,5İstismar yokEPSS %1

    lightbend · play framework5 Kas 2019

  • CVE-2023-31442
    30İzleyin

    In Lightbend Akka before 2.8.1, the async-dns resolver (used by Discovery in DNS mode and transitively by Cluster Bootstrap) uses predictabl

    YüksekCVSS 7,5İstismar yokEPSS %1

    lightbend · akka actor10 May 2023

  • CVE-2021-23339
    26İzleyin

    HTTP Request Smuggling

    OrtaCVSS 6,5İstismar yokEPSS %1

    lightbend · akka-http17 Şub 2021

  • CVE-2020-12480
    26İzleyin

    In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parame

    OrtaCVSS 6,5İstismar yokEPSS %1

    lightbend · play framework17 Ağu 2020

  • CVE-2023-29471
    22İzleyin

    Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain clear

    OrtaCVSS 5,5İstismar yokEPSS %0

    lightbend · alpakka kafka27 Nis 2023

  • CVE-2023-33251
    22İzleyin

    When Akka HTTP before 10.5.2 accepts file uploads via the FileUploadDirectives.fileUploadAll directive, the temporary file it creates has to

    OrtaCVSS 5,5İstismar yokEPSS %0

    lightbend · akka http21 May 2023

  • CVE-2020-28923
    10İzleyin

    An issue was discovered in Play Framework 2.8.0 through 2.8.4.

    DüşükCVSS 2,7İstismar yokEPSS %1

    lightbend · play framework3 Ara 2020