CVE Vulnerabilities

CVE-2014-7808

Published: Sep 15, 2017 | Modified: Nov 07, 2023
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.

Affected Software

Name Vendor Start Version End Version
Wicket Apache 1.5.0 (including) 1.5.13 (excluding)
Wicket Apache 6.0.0 (including) 6.19.0 (excluding)
Wicket Apache 7.0.0-milestone1 (including) 7.0.0-milestone1 (including)
Wicket Apache 7.0.0-milestone2 (including) 7.0.0-milestone2 (including)
Wicket Apache 7.0.0-milestone3 (including) 7.0.0-milestone3 (including)
Wicket Apache 7.0.0-milestone4 (including) 7.0.0-milestone4 (including)
Wicket Apache 7.0.0-milestone5 (including) 7.0.0-milestone5 (including)

References