Vulnerabilities > Apache > Wicket > High

DATE CVE VULNERABILITY TITLE RISK
2021-05-25 CVE-2021-23937 Information Exposure vulnerability in Apache Wicket
A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly sanitized.
network
low complexity
apache CWE-200
7.5
2020-08-11 CVE-2020-11976 Files or Directories Accessible to External Parties vulnerability in Apache Fortress and Wicket
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates.
network
low complexity
apache CWE-552
7.5
2017-10-30 CVE-2014-3526 Information Exposure vulnerability in Apache Wicket
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
network
low complexity
apache CWE-200
7.5
2017-10-03 CVE-2016-6806 Cross-Site Request Forgery (CSRF) vulnerability in Apache Wicket
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests.
network
low complexity
apache CWE-352
8.8
2017-09-15 CVE-2014-7808 Cryptographic Issues vulnerability in Apache Wicket
Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.
network
low complexity
apache CWE-310
7.5