CVE-2022-31023 affects Play Framework versions prior to 2.8.16, allowing the generation of verbose error messages containing sensitive information in production environments. This occurs due to improper configuration or inadvertent use of the static DefaultHttpErrorHandler object, which is designed for development mode. With a CVSS score of 7.5 (HIGH), this vulnerability could lead to sensitive information disclosure (C:H) without requiring user interaction or complex attack vectors (AV:N/AC:L/PR:N/UI:N). There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed in the KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.8.16CPE matchmatch criteria | cpe:2.3:a:lightbend:play_framework:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.