Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2020-9491 Vulnerability in maven package org.apache.nifi:nifi-bootstrap
CVE-2020-2232 Vulnerability in maven package org.jenkins-ci.plugins:email-ext
CVE-2016-3084 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-login
CVE-2023-24428 Vulnerability in maven package org.jenkins-ci.plugins:bitbucket-oauth
CVE-2021-21687 Vulnerability in maven package org.jenkins-ci.main:jenkins-core