XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attackers to read arbitrary files, cause a denial of service, or have unspecified other impact via crafted XML data.
https://playframework.com/security/vulnerability/CVE-2014-3630-XmlExternalEntity
https://groups.google.com/forum/#%21topic/play-framework/WdbFvemsFDQ
https://groups.google.com/forum/#%21msg/play-framework/7uNX_ImTW08/AogWSjsTAyQJ