Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45957
HistoryMar 21, 2024 - 5:49 a.m.

Cross-Site Request Forgery (CSRF)

2024-03-2105:49:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
cross-site request forgery
csrf
vulnerability
apache wicket
fetchmetadataresourceisolationpolicy

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.0%

Apache Wicket is vulnerable to Cross-Site Request Forgery (CSRF). The vulnerability is caused due to an error in the evaluation of the fetch metadata headers within FetchMetadataResourceIsolationPolicy.java. This allows an attacker to bypass the Cross-Site Request Forgery (CSRF) protection mechanism.

AI Score

6.9

Confidence

High

EPSS

0

Percentile

9.0%