Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2023-29509 Vulnerability in maven package org.xwiki.platform:xwiki-platform-flamingo-theme-ui
CVE-2022-36885 Vulnerability in maven package com.coravy.hudson.plugins.github:github
CVE-2021-41183 Vulnerability in maven package org.webjars.npm:jquery-ui
CVE-2012-4386 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2021-21685 Vulnerability in maven package org.jenkins-ci.main:jenkins-core