CVE-2024-27439

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
19/03/2024
Last modified:
27/06/2025

Description

An error in the evaluation of the fetch metadata headers could allow a bypass of the CSRF protection in Apache Wicket.<br /> This issue affects Apache Wicket: from 9.1.0 through 9.16.0, and the milestone releases for the 10.0 series.<br /> Apache Wicket 8.x does not support CSRF protection via the fetch metadata headers and as such is not affected.<br /> <br /> Users are recommended to upgrade to version 9.17.0 or 10.0.0, which fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:wicket:*:*:*:*:*:*:*:* 9.1.0 (including) 9.17.0 (excluding)
cpe:2.3:a:apache:wicket:10.0.0:milestone1:*:*:*:*:*:*
cpe:2.3:a:apache:wicket:10.0.0:milestone2:*:*:*:*:*:*