CVE-2014-7808

HIGH

Apache Wicket < 1.5.13, 6.x < 6.19.0, and 7.x < 7.0.0-M5 - Predictable Encrypted URLs via CryptoMapper

Title source: llm
STIX 2.1

Description

Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.

Scores

CVSS v3 7.5
EPSS 0.0027
EPSS Percentile 50.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-310
Status published
Products (3)
apache/wicket 7.0.0 milestone1 (5 CPE variants)
apache/wicket 1.5.0 - 1.5.13
org.apache.wicket/wicket-core 0 - 1.5.13Maven
Published Sep 15, 2017
Tracked Since Feb 18, 2026