Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2013-2133 Vulnerability in maven package org.wildfly:wildfly-ejb3
CVE-2022-35924 Vulnerability in npm package next-auth
CVE-2009-2901 Vulnerability in maven package org.apache.tomcat:catalina
CVE-2022-34813 Vulnerability in maven package org.jenkins-ci.plugins:xpath-config-viewer
CVE-2023-22832 Vulnerability in maven package org.apache.nifi:nifi-ccda-processors