HIGH 7.5 Maven
Apache Wicket insecure defaults
GHSA-vfmm-jm4v-7frq · CVE-2014-7808
Published · Modified
Description
Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2014-7808
- WEB https://github.com/apache/wicket/commit/d2b8848346b8f806e747dca18799d70c37fc893f
- PACKAGE https://github.com/apache/wicket
- WEB https://lists.apache.org/thread/rqy6lpo5mzco85cbf65r53vdh87gz77b
- WEB https://web.archive.org/web/20180830051017/https://www.smrrd.de/cve-2014-7808-apache-wicket-csrf-2014.html
Ready to move
Start Securing
Free, no credit card | First findings in minutes