Description
An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data Amplification. This affects users migrating from a Play version prior to 2.8.0 that used the Play Java API to serialize classes with protected or private fields to JSON.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1198 | An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data Amplification. This affects users migrating from a Play version prior to 2.8.0 that used the Play Java API to serialize classes with protected or private fields to JSON. |
Github GHSA |
GHSA-v9mf-jgq3-c28h | Data Amplification in Play Framework |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T16:41:00.239Z
Reserved: 2020-11-18T00:00:00.000Z
Link: CVE-2020-28923
No data.
Status : Modified
Published: 2020-12-03T17:15:13.287
Modified: 2024-11-21T05:23:18.150
Link: CVE-2020-28923
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA