Description
An issue was discovered in PlayJava in Play Framework 2.6.0 through 2.8.2. The body parsing of HTTP requests eagerly parses a payload given a Content-Type header. A deep JSON structure sent to a valid POST endpoint (that may or may not expect JSON payloads) causes a StackOverflowError and Denial of Service.
Remediation
References
Related Vulnerabilities
WordPress Plugin WebARX Cross-Site Scripting (1.3.0)
Jboss EAP Improper Input Validation Vulnerability (CVE-2020-1732)
WordPress Plugin WOOCS-Currency Switcher for WooCommerce Professional Cross-Site Scripting (1.3.7.4)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2009-3230)