XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
References
Link | Resource |
---|---|
https://playframework.com/security/vulnerability/CVE-2014-3630-XmlExternalEntity | Issue Tracking Mitigation Vendor Advisory |
https://infocon.org/cons/SyScan/SyScan%202015%20Singapore/SyScan%202015%20Singapore%20presentations/SyScan15%20David%20Jorm%20-%20Finding%20and%20exploiting%20novel%20flaws%20in%20Java%20software.pdf | Issue Tracking Third Party Advisory |
https://groups.google.com/forum/#!topic/play-framework/WdbFvemsFDQ | Third Party Advisory |
https://groups.google.com/forum/#!msg/play-framework/7uNX_ImTW08/AogWSjsTAyQJ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-12-29 14:29
Updated : 2019-11-25 08:25
NVD link : CVE-2014-3630
Mitre link : CVE-2014-3630
JSON object : View
CWE
CWE-611
Improper Restriction of XML External Entity Reference
Products Affected
lightbend
- play_framework
playframework
- play_framework