CVE-2016-6806
Summary
| CVE | CVE-2016-6806 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-03 01:29:00 UTC |
| Updated | 2023-11-07 02:34:00 UTC |
| Description | Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP header into account when no Origin was provided. Furthermore, not all Wicket server side targets were subjected to the CSRF check. This was also fixed. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Wicket | 6.20.0 | All | All | All |
| Application | Apache | Wicket | 6.21.0 | All | All | All |
| Application | Apache | Wicket | 6.22.0 | All | All | All |
| Application | Apache | Wicket | 6.23.0 | All | All | All |
| Application | Apache | Wicket | 6.24.0 | All | All | All |
| Application | Apache | Wicket | 7.0.0 | All | All | All |
| Application | Apache | Wicket | 7.1.0 | All | All | All |
| Application | Apache | Wicket | 7.2.0 | All | All | All |
| Application | Apache | Wicket | 7.3.0 | All | All | All |
| Application | Apache | Wicket | 7.4.0 | All | All | All |
| Application | Apache | Wicket | 8.0.0 | m1 | All | All |
| Application | Apache | Wicket | 6.20.0 | All | All | All |
| Application | Apache | Wicket | 6.21.0 | All | All | All |
| Application | Apache | Wicket | 6.22.0 | All | All | All |
| Application | Apache | Wicket | 6.23.0 | All | All | All |
| Application | Apache | Wicket | 6.24.0 | All | All | All |
| Application | Apache | Wicket | 7.0.0 | All | All | All |
| Application | Apache | Wicket | 7.1.0 | All | All | All |
| Application | Apache | Wicket | 7.2.0 | All | All | All |
| Application | Apache | Wicket | 7.3.0 | All | All | All |
| Application | Apache | Wicket | 7.4.0 | All | All | All |
| Application | Apache | Wicket | 8.0.0 | m1 | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | Mailing List, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.