Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2016-4055 Vulnerability in maven package org.webjars.npm:moment
CVE-2020-5410 Vulnerability in maven package org.springframework.cloud:spring-cloud-config-server
CVE-2014-3120 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2022-22932 Vulnerability in maven package org.apache.karaf:apache-karaf