GHSA-hmhg-95wh-r699

    Dashboard / Vulnerabilities / GHSA-hmhg-95wh-r699

    GHSA-hmhg-95wh-r699

    Published: 24 May 2022Last Modified: 16 Feb 2024

    Summary: DNS based denial of service in Apache Wicket

    Details: A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly sanitized. This DNS lookup can be engineered to overload an internal DNS server or to slow down request processing of the Apache Wicket application causing a possible denial of service on either the internal infrastructure or the web application itself. This issue affects Apache Wicket Apache Wicket 9.x version 9.2.0 and prior versions; Apache Wicket 8.x version 8.11.0 and prior versions; Apache Wicket 7.x version 7.17.0 and prior versions and Apache Wicket 6.x version 6.2.0 and later versions.

    Affected packages

    Package

    Name: org.apache.wicket:wicket-core

    Purl: pkg:maven/org.apache.wicket/wicket-core

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 9.0.0
    Fixed -9.3.0

    Affected versions

    9.0.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-hmhg-95wh-r699 | CVE-DB