Back
CVE-2014-3630
CRITICAL
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
Published: Dec 29, 2017
Modified: Jun 17, 2026
CWE-611
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (24)
| Vendor | Product | Version |
|---|---|---|
| lightbend | play_framework | 2.2.0 |
| lightbend | play_framework | 2.2.0 |
| lightbend | play_framework | 2.2.0 |
| lightbend | play_framework | 2.2.0 |
| lightbend | play_framework | 2.2.1 |
| lightbend | play_framework | 2.2.2 |
| lightbend | play_framework | 2.3.0 |
| lightbend | play_framework | 2.3.0 |
| lightbend | play_framework | 2.3.0 |
| lightbend | play_framework | 2.3.1 |
| lightbend | play_framework | 2.3.2 |
| lightbend | play_framework | 2.3.2 |
| lightbend | play_framework | 2.3.2 |
| lightbend | play_framework | 2.3.3 |
| lightbend | play_framework | 2.3.4 |
| playframework | play_framework | 2.2.0 |
| playframework | play_framework | 2.2.1 |
| playframework | play_framework | 2.2.2 |
| playframework | play_framework | 2.2.2 |
| playframework | play_framework | 2.2.2 |
…and 4 more
GitHub Security Advisory GHSA-xpw4-hqm8-rj97
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2...
References (8)
- https://groups.google.com/forum/#%21msg/play-framework/7uNX_ImTW08/AogWSjsTAyQJ
- https://groups.google.com/forum/#%21topic/play-framework/WdbFvemsFDQ
- https://infocon.org/cons/SyScan/SyScan%202015%20Singapore/SyScan%202015%20Singapore%20presentations/SyScan15%20David%20Jorm%20-%20Finding%20and%20exploiting%20novel%20flaws%20in%20Java%20software.pdf Issue Tracking, Third Party Advisory
- https://playframework.com/security/vulnerability/CVE-2014-3630-XmlExternalEntity Issue Tracking, Mitigation, Vendor Advisory
- https://groups.google.com/forum/#%21msg/play-framework/7uNX_ImTW08/AogWSjsTAyQJ
- https://groups.google.com/forum/#%21topic/play-framework/WdbFvemsFDQ
- https://infocon.org/cons/SyScan/SyScan%202015%20Singapore/SyScan%202015%20Singapore%20presentations/SyScan15%20David%20Jorm%20-%20Finding%20and%20exploiting%20novel%20flaws%20in%20Java%20software.pdf Issue Tracking, Third Party Advisory
- https://playframework.com/security/vulnerability/CVE-2014-3630-XmlExternalEntity Issue Tracking, Mitigation, Vendor Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
2.87%
Top 14% most likely to be exploited
Threat Score
40.1 / 100
Data Sources
NVD
EPSS
GitHub