Apache Wicket CVE-2016-6806 Cross Site Request Forgery Vulnerability
BID:101577
Info
Apache Wicket CVE-2016-6806 Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 101577 |
| Class: | Input Validation Error |
| CVE: |
CVE-2016-6806 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2017 12:00AM |
| Updated: | Dec 19 2017 08:00PM |
| Credit: | Gerben Janssen van Doorn |
| Vulnerable: |
Apache Wicket 7.4 Apache Wicket 7.3 Apache Wicket 7.2 Apache Wicket 7.1 Apache Wicket 7.0 Apache Wicket 6.24 Apache Wicket 6.23 Apache Wicket 6.22 Apache Wicket 6.21 Apache Wicket 6.20 Apache Wicket 8.0.0-M1 |
| Not Vulnerable: |
Apache Wicket 7.5 Apache Wicket 8.0.0-M2 |
Discussion
Apache Wicket CVE-2016-6806 Cross Site Request Forgery Vulnerability
Apache Wicket is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions in the context of the affected application. Other attacks are also possible.
Apache Wicket 6.20.0, 6.21.0, 6.22.0, 6.23.0, 6.24.0, 7.0.0, 7.1.0, 7.2.0, 7.3.0, 7.4.0 and 8.0.0-M1 are vulnerable.
Apache Wicket is prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions in the context of the affected application. Other attacks are also possible.
Apache Wicket 6.20.0, 6.21.0, 6.22.0, 6.23.0, 6.24.0, 7.0.0, 7.1.0, 7.2.0, 7.3.0, 7.4.0 and 8.0.0-M1 are vulnerable.
Exploit / POC
Apache Wicket CVE-2016-6806 Cross Site Request Forgery Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Apache Wicket CVE-2016-6806 Cross Site Request Forgery Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Apache Wicket CVE-2016-6806 Cross Site Request Forgery Vulnerability
References:
References:
- Apache Homepage (Apache)
- CVE-2016-6806: Apache Wicket CSRF detection vulnerability (Apache)