Impact
The vulnerability arises from insufficiently random values used in Apache Wicket’s token generation logic, leading to protection mechanism failures and the leakage or omission of Content‑Security‑Policy headers. Classified as CWE‑330 and CWE‑693, the flaw can weaken the application’s ability to enforce CSP, potentially allowing an attacker to bypass or undermine webpage security controls with the same level of access required to deliver malicious payloads.
Affected Systems
Apache Software Foundation: Apache Wicket versions 9.0.0 through 9.23.0 and 10.0.0 through 10.9.0 are vulnerable. Versions 10.10.0 and later contain the fix; earlier and later releases outside these ranges are not affected.
Risk and Exploitability
The CVSS base score of 6.5 indicates moderate severity, while the EPSS score of less than 1% points to a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves interacting with a vulnerable instance that fails to supply proper CSP headers, most likely by sending crafted requests to pages that are missing or leaking CSP directives.
OpenCVE Enrichment