CVE-2020-28923

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/12/2020
Last modified:
07/12/2020

Description

An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data Amplification. This affects users migrating from a Play version prior to 2.8.0 that used the Play Java API to serialize classes with protected or private fields to JSON.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lightbend:play_framework:*:*:*:*:*:*:*:* 2.8.0 (including) 2.8.4 (including)