Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2023-25767 Vulnerability in maven package org.jenkins-ci.plugins:azure-credentials
CVE-2023-45819 Vulnerability in maven package org.webjars.npm:tinymce
CVE-2023-4918 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2012-3451 Vulnerability in maven package org.apache.cxf:cxf-bundle-jaxrs
CVE-2023-31453 Vulnerability in maven package org.apache.inlong:manager-service