Apache Wicket CSRF Detection Flaw in Multiple Versions
CVE-2016-6806
8.8HIGH
What is CVE-2016-6806?
Apache Wicket versions prior to 6.25.0, 7.5.0, and 8.0.0-M1 have a vulnerability that inadequately implements CSRF prevention measures by failing to check the Referer HTTP header in certain scenarios. This oversight potentially allows malicious exploitation via cross-origin requests, as not all server-side targets within Wicket were subjected to CSRF checks. Mitigational measures require the inclusion of both the Origin and Referer headers to enhance the framework's security.
Affected Version(s)
Apache Wicket 6.20.0
Apache Wicket 6.21.0
Apache Wicket 6.22.0