Bug 2270332 (CVE-2024-27439) - CVE-2024-27439 apache-wicket: Possible bypass of CSRF protection
Summary: CVE-2024-27439 apache-wicket: Possible bypass of CSRF protection
Keywords:
Status: NEW
Alias: CVE-2024-27439
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2270333
TreeView+ depends on / blocked
 
Reported: 2024-03-19 17:16 UTC by Marco Benatto
Modified: 2024-04-06 14:40 UTC (History)
28 users (show)

Fixed In Version: apache-wicket 10.0.0
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Marco Benatto 2024-03-19 17:16:57 UTC
An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket.
This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series.
Apache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected.

Users are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.

https://lists.apache.org/thread/o825rvjjtmz3qv21ps5k7m2w9193g1lo


Note You need to log in before you can comment on or make changes to this bug.