9.8

CVE-2014-3630

XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
LightbendPlay Framework Version2.2.0 Update-
LightbendPlay Framework Version2.2.0 Updatemilestone1
LightbendPlay Framework Version2.2.0 Updatemilestone2
LightbendPlay Framework Version2.2.0 Updatemilestone3
LightbendPlay Framework Version2.2.1 Update-
LightbendPlay Framework Version2.2.2 Update-
LightbendPlay Framework Version2.3.0 Update-
LightbendPlay Framework Version2.3.0 Updaterc1
LightbendPlay Framework Version2.3.0 Updaterc2
LightbendPlay Framework Version2.3.1
LightbendPlay Framework Version2.3.2 Update-
LightbendPlay Framework Version2.3.2 Updaterc1
LightbendPlay Framework Version2.3.2 Updaterc2
LightbendPlay Framework Version2.3.3
LightbendPlay Framework Version2.3.4
PlayframeworkPlay Framework Version2.2.0 Updaterc1
PlayframeworkPlay Framework Version2.2.1 Updaterc1
PlayframeworkPlay Framework Version2.2.2 Updaterc1
PlayframeworkPlay Framework Version2.2.2 Updaterc2
PlayframeworkPlay Framework Version2.2.2 Updaterc3
PlayframeworkPlay Framework Version2.2.2 Updaterc4
PlayframeworkPlay Framework Version2.2.3
PlayframeworkPlay Framework Version2.2.4
PlayframeworkPlay Framework Version2.2.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.71% 0.712
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.