In Play Framework 2.6.0 through 2.8.1, the CSRF filter can be bypassed by making CORS simple requests with content types that contain parameters that can't be parsed.
| Software | From | Fixed in |
|---|---|---|
| lightbend / play_framework | 2.8.0 | 2.8.1.x |
| lightbend / play_framework | 2.7.0 | 2.7.4.x |
| lightbend / play_framework | 2.6.0 | 2.6.25.x |
com.typesafe.play / play_2.12
|
- | 2.7.5 |
com.typesafe.play / play_2.12
|
2.8.0 | 2.8.2 |