XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    No history.
Information
                Published : 2017-12-29 22:29
Updated : 2025-04-20 01:37
NVD link : CVE-2014-3630
Mitre link : CVE-2014-3630
CVE.ORG link : CVE-2014-3630
JSON object : View
Products Affected
                lightbend
- play_framework
playframework
- play_framework
CWE
                
                    
                        
                        CWE-611
                        
            Improper Restriction of XML External Entity Reference
