An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly parses a payload given a Content-Type header. A deep JSON structure sent to a valid POST endpoint (that may or may not expect JSON payloads) causes a StackOverflowError and Denial of Service.
2020-11-06T14:15:16.377
2024-11-21T05:20:51.060
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | lightbend | play_framework | ≤ 2.6.25 | Yes |
Application | lightbend | play_framework | ≤ 2.7.5 | Yes |
Application | lightbend | play_framework | ≤ 2.8.2 | Yes |