Web Hack List

Collected research

CSRF Protection Bypass in Play Framework

Demonstrates a CSRF bypass caused by disagreement between browsers, Akka HTTP and Play Framework over a multipart boundary containing an extra semicolon. Akka drops the content type, allowing Play's legacy blacklist-based CSRF filter to accept the request.

Record

Researcher
Kevin Joensen and Luca Carettoni
Published by
Doyensec

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Kevin Joensen and Luca Carettoni, first published at the original source. Preserved copies are kept so the citation survives its host.