Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2022-34211 Vulnerability in maven package org.jenkins-ci.plugins:vmware-vrealize-orchestrator
CVE-2020-1942 Vulnerability in maven package org.apache.nifi:nifi-framework
CVE-2016-6816 Vulnerability in maven package org.apache.tomcat:coyote
CVE-2022-34792 Vulnerability in maven package org.jenkins-ci.plugins:recipe
CVE-2022-46769 Vulnerability in maven package org.apache.sling:org.apache.sling.cms.ui