CVE-2020-12480

In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:lightbend:play_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:lightbend:play_framework:*:*:*:*:*:*:*:*

Information

Published : 2020-08-17 14:15

Updated : 2020-08-24 09:52


NVD link : CVE-2020-12480

Mitre link : CVE-2020-12480


JSON object : View

CWE
CWE-352

Cross-Site Request Forgery (CSRF)

Advertisement

dedicated server usa

Products Affected

lightbend

  • play_framework