Vulnerability Description
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lightbend | Play Framework | >= 2.6.0, <= 2.6.25 |
Related Weaknesses (CWE)
References
- https://www.playframework.com/security/vulnerabilityVendor Advisory
- https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklisVendor Advisory
- https://www.playframework.com/security/vulnerabilityVendor Advisory
- https://www.playframework.com/security/vulnerability/CVE-2020-12480-CsrfBlacklisVendor Advisory
FAQ
What is CVE-2020-12480?
CVE-2020-12480 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
How severe is CVE-2020-12480?
CVE-2020-12480 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-12480?
Check the references section above for vendor advisories and patch information. Affected products include: Lightbend Play Framework.