CVE-2020-12480: Lightbend Play Framework
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
Affected products
- Lightbend Play Framework: from 2.6.0, up to and including 2.6.25; from 2.7.0, up to and including 2.7.4; from 2.8.0, up to and including 2.8.1
Published 2020-08-17. Last modified 2026-06-17.