CVE-2016-6806
published 2017-10-03CVE-2016-6806: Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The…
PriorityP337high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
0.82%
53.0th percentile
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP header into account when no Origin was provided. Furthermore, not all Wicket server side targets were subjected to the CSRF check. This was also fixed.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache | wicket | — | — |
| apache_software_foundation | apache_wicket | — | — |
| apache_software_foundation | apache_wicket | — | — |
| apache_software_foundation | apache_wicket | — | — |
| apache_software_foundation | apache_wicket | — | — |
| apache_software_foundation | apache_wicket | — | — |
| apache_software_foundation | apache_wicket | — | — |
| apache_software_foundation | apache_wicket | — | — |
| apache_software_foundation | apache_wicket | — | — |
| apache_software_foundation | apache_wicket | — | — |
| apache_software_foundation | apache_wicket | — | — |
| apache_software_foundation | apache_wicket | — | — |
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Wicket vulnerable to CSRF attacks
osv·2022-05-17
CVE-2016-6806 [HIGH] Apache Wicket vulnerable to CSRF attacks
Apache Wicket vulnerable to CSRF attacks
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP header into account when no Origin was provided. Furthermore, not all Wicket server side targets were subjected to the CSRF check. This was also fixed.
GHSA
Apache Wicket vulnerable to CSRF attacks
ghsa·2022-05-17
CVE-2016-6806 [HIGH] CWE-352 Apache Wicket vulnerable to CSRF attacks
Apache Wicket vulnerable to CSRF attacks
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP header into account when no Origin was provided. Furthermore, not all Wicket server side targets were subjected to the CSRF check. This was also fixed.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-03
Published