First published: Tue Nov 05 2019(Updated: )
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the target host.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lightbend Play Framework | >=2.5.0<=2.5.19 | |
Lightbend Play Framework | >=2.6.0<=2.6.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-17598 is a vulnerability in Lightbend Play Framework 2.5.x through 2.6.23 that exposes proxy credentials to the target host.
CVE-2019-17598 affects you if you are using Lightbend Play Framework 2.5.x through 2.6.23 with an authenticated HTTP proxy and making requests over HTTPS.
CVE-2019-17598 has a severity rating of 7.5 (High).
To fix CVE-2019-17598, upgrade your Lightbend Play Framework installation to a version beyond 2.6.23.
You can find more information about CVE-2019-17598 on the official Play Framework security vulnerability page and the specific CVE page.