{"id":"GHSA-442g-gcg6-mhm4","summary":"Play Framework Inadequate Encryption Strength vulnerability","details":"An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the target host.","aliases":["CVE-2019-17598"],"modified":"2023-11-01T04:50:44.315859Z","published":"2022-05-24T22:01:04Z","database_specific":{"github_reviewed_at":"2022-11-22T19:04:39Z","nvd_published_at":"2019-11-05T15:15:00Z","cwe_ids":["CWE-326"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-17598"},{"type":"WEB","url":"https://www.playframework.com/security/vulnerability"},{"type":"WEB","url":"https://www.playframework.com/security/vulnerability/CVE-2019-17598-PlayWSHttpConnectAuthorizationHeaders"}],"affected":[{"package":{"name":"com.typesafe.play:play-ws_2.12","ecosystem":"Maven","purl":"pkg:maven/com.typesafe.play/play-ws_2.12"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.5.0"},{"fixed":"2.6.24"}]}],"versions":["2.6.0","2.6.0-M1","2.6.0-M2","2.6.0-M3","2.6.0-M4","2.6.0-M5","2.6.0-RC1","2.6.0-RC2","2.6.1","2.6.10","2.6.11","2.6.12","2.6.13","2.6.14","2.6.15","2.6.16","2.6.17","2.6.18","2.6.19","2.6.2","2.6.20","2.6.21","2.6.22","2.6.23","2.6.3","2.6.5","2.6.6","2.6.7","2.6.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-442g-gcg6-mhm4/GHSA-442g-gcg6-mhm4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}