Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2022-22984 Vulnerability in npm package snyk-gradle-plugin
CVE-2022-41230 Vulnerability in maven package org.jenkins-ci.plugins:build-publisher
CVE-2022-26477 Vulnerability in maven package org.apache.systemds:systemds
CVE-2015-0254 Vulnerability in maven package jstl:jstl
CVE-2019-10298 Vulnerability in maven package org.jenkins-ci.plugins:koji