Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2015-7499 Vulnerability in npm package libxmljs
CVE-2022-34202 Vulnerability in maven package com.geteasyqa:easyqa
CVE-2021-42550 Vulnerability in maven package ch.qos.logback:logback-core
CVE-2023-35142 Vulnerability in maven package com.checkmarx.jenkins:checkmarx
CVE-2023-47112 Vulnerability in maven package org.rundeck:rundeck