Play Framework

Vendor:

First CVE: Oct 18, 2017 · Active for 8 years

11
Total CVEs
More Total CVEs than 89% of tracked products
2.2
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Play Framework over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2017
8 years ago
Most Recent CVE
Jun 2, 2022
1,514 days ago

CVE Severity & Scoring

Play Framework11 CVEs
All CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None10 (90.9%)
Unknown0 (0.0%)
Required1 (9.1%)
Privileges Required
Low0 (0.0%)
High1 (9.1%)
None10 (90.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, c
Dec 29, 20179.831NONO
A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when running on Windows. It allows a remote at
Jul 17, 20187.525NONO
Play Framework is a web framework for Java and Scala. Verions prior to 2.8.16 are vulnerable to generation of error messages containing sensitive information. Play Framework, when
Jun 2, 20227.524NONO
Play Framework is a web framework for Java and Scala. A denial of service vulnerability has been discovered in verions 2.8.3 through 2.8.15 of Play's forms library, in both the Sca
Jun 2, 20227.524NONO
An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly parses a payload given a Content-Type header. A deep JSON struc
Nov 6, 20207.524NONO
In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.
Nov 6, 20207.524NONO
In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.
Nov 6, 20207.524NONO
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under
Nov 5, 20197.523NONO
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to by
Oct 18, 20177.523NONO
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Aug 17, 20206.517NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Play Framework

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.3.817.55.4%00
2.3.717.55.4%00
2.3.617.55.4%00
2.3.517.55.4%00
2.3.428.74.2%00
2.3.328.74.2%00
2.3.228.74.2%00
2.3.128.74.2%00
2.3.028.74.2%00
2.2.617.55.4%00
2.2.228.74.2%00
2.2.128.74.2%00
2.2.029.33.4%00
2.1.117.55.4%00
2.1.017.55.4%00
2.0.817.55.4%00
2.0.717.55.4%00
2.0.617.55.4%00
2.0.517.55.4%00
2.0.417.55.4%00