ZeroHour

CVE-2020-12480

CVSS 3.1
6.5 medium
EPSS
<1%p43
Published
()
Modified
Description

In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.

Vendors
lightbend
Products
play framework
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.