CVE-2016-6806

HIGH

Apache Wicket 6.x < 6.25.0, 7.x < 7.5.0, 8.0.0-M1 - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Description

Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP header into account when no Origin was provided. Furthermore, not all Wicket server side targets were subjected to the CSRF check. This was also fixed.

References (1)

Core 1

Scores

CVSS v3 8.8
EPSS 0.0017
EPSS Percentile 37.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (23)
apache/wicket 6.20.0
apache/wicket 6.21.0
apache/wicket 6.22.0
apache/wicket 6.23.0
apache/wicket 6.24.0
apache/wicket 7.0.0
apache/wicket 7.1.0
apache/wicket 7.2.0
apache/wicket 7.3.0
apache/wicket 7.4.0
... and 13 more
Published Oct 03, 2017
Tracked Since Feb 18, 2026