CVE-2022-31023
Last modified
CVE-2022-31023 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Play Framework is a web framework for Java and Scala. Verions prior to 2.8.16 are vulnerable to generation of error messages containing sensitive information. EPSS estimates a 1.23% chance of exploitation in the next 30 days.
Description
Play Framework is a web framework for Java and Scala. Verions prior to 2.8.16 are vulnerable to generation of error messages containing sensitive information. Play Framework, when run in dev mode, shows verbose errors for easy debugging, including an exception stack trace. Play does this by configuring its `DefaultHttpErrorHandler` to do so based on the application mode. In its Scala API Play also provides a static object `DefaultHttpErrorHandler` that is configured to always show verbose errors. This is used as a default value in some Play APIs, so it is possible to inadvertently use this version in production. It is also possible to improperly configure the `DefaultHttpErrorHandler` object instance as the injected error handler. Both of these situations could result in verbose errors displaying to users in a production application, which could expose sensitive information from the application. In particular, the constructor for `CORSFilter` and `apply` method for `CORSActionBuilder` use the static object `DefaultHttpErrorHandler` as a default value. This is patched in Play Framework 2.8.16. The `DefaultHttpErrorHandler` object has been changed to use the prod-mode behavior, and `DevHttpErrorHandler` has been introduced for the dev-mode behavior. A workaround is available. When constructing a `CORSFilter` or `CORSActionBuilder`, ensure that a properly-configured error handler is passed. Generally this should be done by using the `HttpErrorHandler` instance provided through dependency injection or through Play's `BuiltInComponents`. Ensure that the application is not using the `DefaultHttpErrorHandler` static object in any code that may be run in production.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lightbend | Play Framework | < 2.8.16 |
References
- https://github.com/playframework/playframework/pull/11305Issue Tracking, Patch, Third Party Advisory
- https://github.com/playframework/playframework/releases/tag/2.8.16Release Notes, Third Party Advisory
- https://github.com/playframework/playframework/security/advisories/GHSA-p9p4-97g9-wcrhMitigation, Third Party Advisory
- https://github.com/playframework/playframework/pull/11305Issue Tracking, Patch, Third Party Advisory
- https://github.com/playframework/playframework/releases/tag/2.8.16Release Notes, Third Party Advisory
- https://github.com/playframework/playframework/security/advisories/GHSA-p9p4-97g9-wcrhMitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-31023?
How severe is CVE-2022-31023?
How do I fix CVE-2022-31023?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-31017Zulip is an open-source team collaboration tool. Versions 2.…2.6
- CVE-2022-31018Play Framework is a web framework for Java and Scala. A deni…7.5
- CVE-2022-31019Vapor is a server-side Swift HTTP web framework. When using …7.5
- CVE-2022-31020Indy Node is the server portion of a distributed ledger purp…8.8
- CVE-2022-31021Ursa is a cryptographic library for use with blockchains. A …5.3
- CVE-2022-31022Bleve is a text indexing library for go. Bleve includes HTTP…5.5
- CVE-2022-31024richdocuments is the repository for NextCloud Collabra, the …6.5
- CVE-2022-31025Discourse is an open source platform for community discussio…5.3
- CVE-2022-31026Trilogy is a client library for MySQL. When authenticating, …7.5
- CVE-2022-31027OAuthenticator is an OAuth token library for the JupyerHub l…6.5
- CVE-2022-31028MinIO is a multi-cloud object storage solution. Starting wit…7.5
- CVE-2022-31029AdminLTE is a Pi-hole Dashboard for stats and configuration.…4.8
Are you affected by CVE-2022-31023?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
