An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket. This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series. Apache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected. Users are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-03-19T11:07:47.648Z

Updated: 2024-08-22T14:09:14.488Z

Reserved: 2024-02-25T20:15:40.414Z

Link: CVE-2024-27439

cve-icon Vulnrichment

Updated: 2024-08-02T00:34:52.295Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-19T11:15:06.537

Modified: 2024-05-01T18:15:16.380

Link: CVE-2024-27439

cve-icon Redhat

Severity : Important

Publid Date: 2024-03-19T00:00:00Z

Links: CVE-2024-27439 - Bugzilla