Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2014-0050 Vulnerability in maven package commons-fileupload:commons-fileupload
CVE-2023-4061 Vulnerability in maven package org.wildfly.core:wildfly-controller
CVE-2021-22144 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2019-10288 Vulnerability in maven package de.e-nexus:jabber-server-plugin
CVE-2023-49378 Vulnerability in maven package com.jfinal:jfinal