7.5

CVE-2014-7808

Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Wicket Version >= 1.5.0 < 1.5.13
Apache ≫ Wicket Version >= 6.0.0 < 6.19.0
Apache ≫ Wicket Version 7.0.0 Update milestone1
Apache ≫ Wicket Version 7.0.0 Update milestone2
Apache ≫ Wicket Version 7.0.0 Update milestone3
Apache ≫ Wicket Version 7.0.0 Update milestone4
Apache ≫ Wicket Version 7.0.0 Update milestone5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.11% 0.615
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://mail-archives.apache.org/mod_mbox/wicket-users/201502.mbox/%3CCAMomwMpLPDYezc=iFofm1R1Uq37vUFJ8VC-_ex5SU8-HAKBoRw%40mail.gmail.com%3E
https://www.smrrd.de/cve-2014-7808-apache-wicket-csrf-2014.html
Third Party Advisory