In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| com.typesafe.play:play_2.12(Maven) | 0 | 2.7.5 | N/A |
| com.typesafe.play:play_2.12(Maven) | 2.8.0 | 2.8.2 | N/A |
CVSS Metrics