Play Framework XML External Entities Information Disclosure Vulnerability
BID:62352
Info
Play Framework XML External Entities Information Disclosure Vulnerability
| Bugtraq ID: | 62352 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2013 12:00AM |
| Updated: | Sep 11 2013 12:00AM |
| Credit: | Australia Post Digital Mailbox Security Team |
| Vulnerable: |
Play Framework Play Framework 2.1.3 Play Framework Play Framework 2.1.2 Play Framework Play Framework 2.1.1 Play Framework Play Framework 2.1.0 Play Framework Play Framework 2.0.6 Play Framework Play Framework 2.0.5 Play Framework Play Framework 2.0.4 Play Framework Play Framework 2.0.3 Play Framework Play Framework 2.0.2 Play Framework Play Framework 2.0.1 Play Framework Play Framework 2.0 |
| Not Vulnerable: |
Play Framework Play Framework 2.1.4 Play Framework Play Framework 2.0.7 |
Discussion
Play Framework XML External Entities Information Disclosure Vulnerability
Play Framework is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks. This attacker may also exploit this issue to cause excessive memory and CPU consumption resulting in denial-of-service conditions.
Play Framework versions 2.1.0 through 2.1.3 and 2.0 through 2.0.6 are vulnerable.
Play Framework is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information; this may lead to further attacks. This attacker may also exploit this issue to cause excessive memory and CPU consumption resulting in denial-of-service conditions.
Play Framework versions 2.1.0 through 2.1.3 and 2.0 through 2.0.6 are vulnerable.
Exploit / POC
Play Framework XML External Entities Information Disclosure Vulnerability
An attacker can exploit this issue using readily available tools.
An attacker can exploit this issue using readily available tools.
Solution / Fix
Play Framework XML External Entities Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.