Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2015-5211 Vulnerability in maven package org.springframework:spring-web
CVE-2019-3888 Vulnerability in maven package io.undertow:undertow-core
CVE-2023-50773 Vulnerability in maven package com.zintow:dingding-json-pusher
CVE-2020-5403 Vulnerability in maven package io.projectreactor.netty:reactor-netty
CVE-2021-33605 Vulnerability in maven package com.vaadin:vaadin-checkbox-flow