A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when running on Windows. It allows a remote attacker to download arbitrary files from the target server via specially crafted HTTP requests.
{ "nvd_published_at": "2018-07-17T12:29:00Z", "github_reviewed_at": "2022-11-22T19:45:54Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-22" ] }