Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Remediation
References
https://www.playframework.com/security/vulnerability
https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypass
Related Vulnerabilities
CVE-2023-44487 Vulnerability in maven package io.netty:netty-codec-http2
CVE-2020-1960 Vulnerability in maven package org.apache.flink:flink-metrics-core
CVE-2021-45046 Vulnerability in maven package org.apache.logging.log4j:log4j-core
CVE-2019-16550 Vulnerability in maven package org.jenkins-ci.plugins.m2release:m2release
CVE-2022-34783 Vulnerability in maven package org.jenkins-ci.plugins:plot