An issue was discovered in Lightbend Play Framework 2.5.x through 2.6.23. When configured to make requests using an authenticated HTTP proxy, play-ws may sometimes, typically under high load, when connecting to a target host using https, expose the proxy credentials to the target host.
{
"cpe": "cpe:2.3:a:lightbend:play_framework:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "2.5.0"
},
{
"last_affected": "2.5.19"
},
{
"introduced": "2.6.0"
},
{
"last_affected": "2.6.23"
}
],
"source": "CPE_RANGE"
}