CVE-2016-6806
HIGHApache Wicket 6.x < 6.25.0, 7.x < 7.5.0, 8.0.0-M1 - Cross-Site Request Forgery
Title source: llmDescription
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP header into account when no Origin was provided. Furthermore, not all Wicket server side targets were subjected to the CSRF check. This was also fixed.
References (1)
Core 1
Core References
Mailing List mailing-list
x_refsource_mlist
https://lists.apache.org/thread.html/074b72585f4b7c6adda1af52aecbfe1be23c6d6f5bb9382270f059cd%40%3Cannounce.apache.org%3E
Scores
CVSS v3
8.8
EPSS
0.0017
EPSS Percentile
37.1%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Details
CWE
CWE-352
Status
published
Products (23)
apache/wicket
6.20.0
apache/wicket
6.21.0
apache/wicket
6.22.0
apache/wicket
6.23.0
apache/wicket
6.24.0
apache/wicket
7.0.0
apache/wicket
7.1.0
apache/wicket
7.2.0
apache/wicket
7.3.0
apache/wicket
7.4.0
... and 13 more
Published
Oct 03, 2017
Tracked Since
Feb 18, 2026