CVE-2019-17598: Weak Encryption
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the target host.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-17598?
CVE-2019-17598 is a vulnerability in Lightbend Play Framework 2.5.x through 2.6.23 that exposes proxy credentials to the target host.
How does CVE-2019-17598 affect me?
CVE-2019-17598 affects you if you are using Lightbend Play Framework 2.5.x through 2.6.23 with an authenticated HTTP proxy and making requests over HTTPS.
What is the severity of CVE-2019-17598?
CVE-2019-17598 has a severity rating of 7.5 (High).
How do I fix CVE-2019-17598?
To fix CVE-2019-17598, upgrade your Lightbend Play Framework installation to a version beyond 2.6.23.
Where can I find more information about CVE-2019-17598?
You can find more information about CVE-2019-17598 on the official Play Framework security vulnerability page and the specific CVE page.