CSRF in Play Framework
Moderate severity
GitHub Reviewed
Published
Aug 18, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Package
Affected versions
< 2.7.5
>= 2.8.0, < 2.8.2
Patched versions
2.7.5
2.8.2
Description
Reviewed
Aug 18, 2020
Published to the GitHub Advisory Database
Aug 18, 2020
Last updated
Jan 9, 2023
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
References