GHSA-p8p6-rcp6-4mrm

Suggest an improvement
Source
https://github.com/advisories/GHSA-p8p6-rcp6-4mrm
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-p8p6-rcp6-4mrm/GHSA-p8p6-rcp6-4mrm.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-p8p6-rcp6-4mrm
Aliases
Published
2022-02-10T20:23:01Z
Modified
2023-11-08T04:03:20.222527Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Uncontrolled Recursion in Play Framework
Details

In Play Framework 2.6.0 through 2.8.2, stack consumption can occur because of unbounded recursion during parsing of crafted JSON documents.

Database specific
{
    "nvd_published_at": "2020-11-06T14:15:00Z",
    "github_reviewed_at": "2021-04-22T16:54:42Z",
    "severity": "HIGH",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-674"
    ]
}
References

Affected packages

Maven / com.typesafe.play:play

Package

Name
com.typesafe.play:play
View open source insights on deps.dev
Purl
pkg:maven/com.typesafe.play/play

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.0
Fixed
2.7.6

Maven / com.typesafe.play:play

Package

Name
com.typesafe.play:play
View open source insights on deps.dev
Purl
pkg:maven/com.typesafe.play/play

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.8.0
Fixed
2.8.3

Maven / com.typesafe.play:play-java

Package

Name
com.typesafe.play:play-java
View open source insights on deps.dev
Purl
pkg:maven/com.typesafe.play/play-java

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.0
Fixed
2.7.6

Maven / com.typesafe.play:play-java

Package

Name
com.typesafe.play:play-java
View open source insights on deps.dev
Purl
pkg:maven/com.typesafe.play/play-java

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.8.0
Fixed
2.8.3