CVE-2014-3630

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
29/12/2017
Last modified:
20/04/2025

Description

XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lightbend:play_framework:2.2.0:-:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.2.0:milestone1:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.2.0:milestone2:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.2.0:milestone3:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.2.1:-:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.2.2:-:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.3.0:-:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.3.0:rc2:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.3.1:*:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.3.2:-:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.3.2:rc1:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.3.2:rc2:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.3.3:*:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:2.3.4:*:*:*:*:*:*:*