Логотип exploitDog
bind:CVE-2024-27439
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-27439

Количество 4

Количество 4

redhat логотип

CVE-2024-27439

почти 2 года назад

An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected. Users are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2024-27439

почти 2 года назад

An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected. Users are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8vvp-525h-cxf9

почти 2 года назад

Cross-Site Request Forgery in Apache Wicket

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2024-02450

почти 2 года назад

Уязвимость фреймворка для создания веб-приложений на языке Java Apache Wicket, связанная с подделкой межсайтовых запросов, позволяющая нарушителю осуществить CSRF-атаку

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-27439

An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected. Users are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.

CVSS3: 8.1
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-27439

An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected. Users are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-8vvp-525h-cxf9

Cross-Site Request Forgery in Apache Wicket

CVSS3: 6.5
0%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-02450

Уязвимость фреймворка для создания веб-приложений на языке Java Apache Wicket, связанная с подделкой межсайтовых запросов, позволяющая нарушителю осуществить CSRF-атаку

CVSS3: 8.1
0%
Низкий
почти 2 года назад

Уязвимостей на страницу