GHSA-vfmm-jm4v-7frq
Dashboard / Vulnerabilities / GHSA-vfmm-jm4v-7frq
Summary: Apache Wicket insecure defaults
Details: Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.
References: https://nvd.nist.gov/vuln/detail/CVE-2014-7808, https://github.com/apache/wicket/commit/d2b8848346b8f806e747dca18799d70c37fc893f, https://github.com/apache/wicket, https://lists.apache.org/thread/rqy6lpo5mzco85cbf65r53vdh87gz77b, https://web.archive.org/web/20180830051017/https://www.smrrd.de/cve-2014-7808-apache-wicket-csrf-2014.html
Affected packages
Package
Name: org.apache.wicket:wicket-core
Purl: pkg:maven/org.apache.wicket/wicket-core
Affected ranges
Type: ECOSYSTEM
Events:
