← Back

CVE-2014-3630

nvd nist
Published: Dec 29, 2017Modified: May 13, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.

Affected (24)

1 product
Play Framework
1 product
Play Framework
Configuration A
24 vulnerable
Vulnerable SoftwareAffected Versions
Lightbend
Version 2.2.0
Version 2.2.0 milestone1
Version 2.2.0 milestone2
Version 2.2.0 milestone3
Version 2.2.1
Version 2.2.2
Version 2.3.0
Version 2.3.0 rc1
Version 2.3.0 rc2
Version 2.3.1
Version 2.3.2
Version 2.3.2 rc1
Version 2.3.2 rc2
Version 2.3.3
Version 2.3.4
Playframework
Version 2.2.0 rc1
Version 2.2.1 rc1
Version 2.2.2 rc1
Version 2.2.2 rc2
Version 2.2.2 rc3
Version 2.2.2 rc4
Version 2.2.3
Version 2.2.4
Version 2.2.5

Timeline

No history available yet.