CVE-2016-6806
Apache Wicket vulnerable to CSRF attacks
8.8
HIGH
CVSS 3.1
EPSS 0.82%
描述
Apache Wicket 6.x before 6.25.0, 7.x before 7.5.0, and 8.0.0-M1 provide a CSRF prevention measure that fails to discover some cross origin requests. The mitigation is to not only check the Origin HTTP header, but also take the Referer HTTP header into account when no Origin was provided. Furthermore, not all Wicket server side targets were subjected to the CSRF check. This was also fixed.
如何修補 CVE-2016-6806
要修補 CVE-2016-6806,請將受影響套件升級到下列已修補版本。
- —升級至 6.25.0 或更新版本
CVE-2016-6806 正在被利用嗎?
低 — EPSS 為 0.8%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 6.20.0, < 6.25.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |