Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2023-35166 Vulnerability in maven package org.xwiki.platform:xwiki-platform-help-ui
CVE-2020-6950 Vulnerability in maven package org.glassfish:jakarta.faces
CVE-2016-6651 Vulnerability in maven package org.cloudfoundry.identity:cloudfoundry-identity-server
CVE-2023-37579 Vulnerability in maven package org.apache.pulsar:pulsar-functions-worker
CVE-2023-32068 Vulnerability in maven package org.xwiki.platform:xwiki-platform-url-api