Low severity2.7NVD Advisory· Published Dec 3, 2020· Updated Jun 17, 2026
CVE-2020-28923
CVE-2020-28923
Description
An issue was discovered in Play Framework 2.8.0 through 2.8.4. Carefully crafted JSON payloads sent as a form field lead to Data Amplification. This affects users migrating from a Play version prior to 2.8.0 that used the Play Java API to serialize classes with protected or private fields to JSON.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
com.typesafe.play:playMaven | >= 2.8.0, < 2.8.5 | 2.8.5 |
Affected products
3- Play Framework/Play Frameworkdescription
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-v9mf-jgq3-c28hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-28923ghsaADVISORY
- www.playframework.com/security/vulnerabilitynvdVendor AdvisoryWEB
- www.playframework.com/security/vulnerability/CVE-2020-28923-ImproperRemovalofSensitiveInformationBeforeStorageorTransfernvdVendor AdvisoryWEB
News mentions
0No linked articles in our index yet.