Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2018-1000665 Vulnerability in maven package org.webjars.npm:dojo
CVE-2021-32050 Vulnerability in npm package mongodb
CVE-2022-2237 Vulnerability in npm package keycloak-connect
CVE-2021-23266 Vulnerability in maven package org.craftercms:crafter-engine
CVE-2011-4343 Vulnerability in maven package org.apache.myfaces.core.internal:myfaces-impl-shared