CVE-2014-7808
Martin Grigorov <[email protected]> Wed, 18 Feb 2015 22:18:43 +0200
| Newsgroups | gmane.comp.java.wicket.user,gmane.comp.apache.maven.announce,gmane.comp.apache.incubator.bigtop.devel,gmane.comp.security.full-disclosure,gmane.comp.security.bugtraq |
|---|---|
| Message-ID | <CAMomwMpLPDYezc=iFofm1R1Uq37vUFJ8VC-_ex5SU8-HAKBoRw@mail.gmail.com> |
--047d7b3a8e9205e21d050f628936 Content-Type: text/plain; charset=UTF-8 Severity: Important Vendor: The Apache Software Foundation Versions Affected: Apache Wicket 1.5.12, 6.18.0 and 7.0.0-M4 Description: With Wicket's default security settings the usage of CryptoMapper to encrypt/obfuscate pages' urls is not strong enough. It is possible to predict the encrypted version of an url based on the previous history. The application developers using this feature are recommended to upgrade to: - Apache Wicket 1.5.13 - Apache Wicket 6.19.0 - Apache Wicket 7.0.0-M5 Credit: This issue was reported by Fabian Faessler! Apache Wicket Team --047d7b3a8e9205e21d050f628936--