CVE-2014-3630
29.12.2017, 22:29
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.Enginsight
Vendor | Product | Version |
---|---|---|
lightbend | play_framework | 2.2.0 |
lightbend | play_framework | 2.2.0:milestone1 |
lightbend | play_framework | 2.2.0:milestone2 |
lightbend | play_framework | 2.2.0:milestone3 |
lightbend | play_framework | 2.2.1 |
lightbend | play_framework | 2.2.2 |
lightbend | play_framework | 2.3.0 |
lightbend | play_framework | 2.3.0:rc1 |
lightbend | play_framework | 2.3.0:rc2 |
lightbend | play_framework | 2.3.1 |
lightbend | play_framework | 2.3.2 |
lightbend | play_framework | 2.3.2:rc1 |
lightbend | play_framework | 2.3.2:rc2 |
lightbend | play_framework | 2.3.3 |
lightbend | play_framework | 2.3.4 |
playframework | play_framework | 2.2.0:rc1 |
playframework | play_framework | 2.2.1:rc1 |
playframework | play_framework | 2.2.2:rc1 |
playframework | play_framework | 2.2.2:rc2 |
playframework | play_framework | 2.2.2:rc3 |
playframework | play_framework | 2.2.2:rc4 |
playframework | play_framework | 2.2.3 |
playframework | play_framework | 2.2.4 |
playframework | play_framework | 2.2.5 |
𝑥
= Vulnerable software versions
References