Don't report any security issue publicly here!
What if you find any security problem with Play framework?
--------------------------------------------------------------------------------------
We strongly encourage folks to report such problems to our private
security mailing list first, before disclosing them in a public forum.
All security bugs in Play should be reported by email to
secu...@playframework.org. This list is delivered to a subset of the
core team who handle security issues.
--
Guillaume Bort, http://guillaume.bort.fr