Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2016-6814 Vulnerability in maven package org.codehaus.groovy:groovy-all
CVE-2012-5886 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2019-10280 Vulnerability in maven package org.jenkins-ci.plugins:assembla-auth
CVE-2015-5209 Vulnerability in maven package org.apache.struts.xwork:xwork-core
CVE-2017-3156 Vulnerability in maven package org.apache.cxf:cxf-rt-rs-security-oauth2