Total vulnerabilities in the database
An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the target host.
Software | From | Fixed in |
---|---|---|
lightbend / play_framework | 2.5.0 | 2.5.19.x |
lightbend / play_framework | 2.6.0 | 2.6.23.x |
![]() |
2.5.0 | 2.6.24 |