Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2020-6467 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-15252 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2019-13416 Vulnerability in maven package com.floragunn:search-guard-6
CVE-2017-8046 Vulnerability in maven package org.springframework.boot:spring-boot-starter-data-rest
CVE-2022-28220 Vulnerability in maven package org.apache.james.protocols:protocols-netty