VulnerabilityModified
CVE-2020-12480
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
MEDIUM 6.5EPSS 0.53%
Does this matter?
Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.
Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
- EPSS
- 0.53% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- lightbend/play framework
- Source
- cve@mitre.org
References
- https://www.playframework.com/security/vulnerabilityVendor Advisory
- https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypassVendor Advisory
- https://www.playframework.com/security/vulnerabilityVendor Advisory
- https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklistBypassVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.