CVE-2020-26882: High severity play framework vulnerability
Published Nov 6, 2020
·Updated
In Play Framework 2.6.0 through 2.8.2, data amplification can occur when an application accepts multipart/form-data JSON input.
Affected Software
3 affected components
Lightbend Play Framework<=2.6.25
Lightbend Play Framework>=2.7.0<=2.7.5
Lightbend Play Framework>=2.8.0<=2.8.2
Event History
Nov 6, 2020
CVE Published
via MITRE·01:26 PM
Data Sourced
via MITRE·01:26 PM
Description
Frequently Asked Questions
1
What is CVE-2020-26882?
CVE-2020-26882 is a vulnerability that allows data amplification in Play Framework versions 2.6.0 through 2.8.2.
2
How does CVE-2020-26882 occur?
CVE-2020-26882 occurs when an application accepts multipart/form-data JSON input in Play Framework versions 2.6.0 through 2.8.2.
3
What is the severity of CVE-2020-26882?
The severity of CVE-2020-26882 is high with a CVSS score of 7.5.
4
Which software versions are affected by CVE-2020-26882?
Play Framework versions 2.6.0 through 2.8.2 are affected by CVE-2020-26882.
5
How can I fix CVE-2020-26882?
To fix CVE-2020-26882, you should upgrade your Play Framework installation to a version beyond 2.8.2.