CVEs Blog | G5 Cyber Security

CVE-2020-27196 – An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2

An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly parses a payload given a Content-Type header. A deep JSON structure sent to a valid POST endpoint (that may or may not expect JSON payloads) causes a StackOverflowError and Denial of Service.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27196

Reference (s):

Exit mobile version