Collected research
CSRF Protection Bypass in Play Framework
Demonstrates a CSRF bypass caused by disagreement between browsers, Akka HTTP and Play Framework over a multipart boundary containing an extra semicolon. Akka drops the content type, allowing Play's legacy blacklist-based CSRF filter to accept the request.
Record
- Researcher
- Kevin Joensen and Luca Carettoni
- Published by
- Doyensec
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Kevin Joensen and Luca Carettoni, first published at the original source. Preserved copies are kept so the citation survives its host.