First published: Mon Aug 17 2020(Updated: )
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lightbend Play Framework | >=2.6.0<=2.6.25 | |
Lightbend Play Framework | >=2.7.0<=2.7.4 | |
Lightbend Play Framework | >=2.8.0<=2.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-12480.
The severity of CVE-2020-12480 is medium with a CVSS score of 6.5.
The CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Play Framework versions 2.6.0 through 2.8.1 are affected by CVE-2020-12480.
To fix the CSRF filter bypass vulnerability, it is recommended to upgrade Play Framework to a version that is not affected, or apply any security patches provided by the vendor.