Apache Wicket CSRF Detection Flaw in Multiple Versions
CVE-2016-6806
8.8HIGH
Summary
Apache Wicket versions prior to 6.25.0, 7.5.0, and 8.0.0-M1 have a vulnerability that inadequately implements CSRF prevention measures by failing to check the Referer HTTP header in certain scenarios. This oversight potentially allows malicious exploitation via cross-origin requests, as not all server-side targets within Wicket were subjected to CSRF checks. Mitigational measures require the inclusion of both the Origin and Referer headers to enhance the framework's security.
Affected Version(s)
Apache Wicket 6.20.0
Apache Wicket 6.21.0
Apache Wicket 6.22.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved