« Volver al listado

CVE-2014-7808

Estado: ModificadaAlta (7.5)—

Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-7808",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-09-15T20:29:00.193",
  "references": [
    {
      "url": "http://mail-archives.apache.org/mod_mbox/wicket-users/201502.mbox/%3CCAMomwMpLPDYezc=iFofm1R1Uq37vUFJ8VC-_ex5SU8-HAKBoRw%40mail.gmail.com%3E",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://www.smrrd.de/cve-2014-7808-apache-wicket-csrf-2014.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://mail-archives.apache.org/mod_mbox/wicket-users/201502.mbox/%3CCAMomwMpLPDYezc=iFofm1R1Uq37vUFJ8VC-_ex5SU8-HAKBoRw%40mail.gmail.com%3E",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.smrrd.de/cve-2014-7808-apache-wicket-csrf-2014.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-310"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider."
    },
    {
      "lang": "es",
      "value": "Apache Wicket en versiones anteriores a la 1.5.13, 6.x anteriores a la 6.19.0 y 7.x anteriores a la 7.0.0-M5 facilita que los atacantes superen el mecanismo de protección criptográfica y predigan URL cifradas aprovechando el uso de CryptoMapper como proveedor por defecto de cifrado."
    }
  ],
  "lastModified": "2026-06-17T00:15:43.690",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:apache:wicket:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AE2A0CF-ADE9-4708-B3E8-2FD5DC7E5FF5",
              "versionEndExcluding": "1.5.13",
              "versionStartIncluding": "1.5.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:wicket:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F935C3AF-B4F6-48BA-879F-C916CA6C2D0E",
              "versionEndExcluding": "6.19.0",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:apache:wicket:7.0.0:milestone1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AADF9D31-21F8-45AD-8B85-86244D4529F7"
            },
            {
              "criteria": "cpe:2.3:a:apache:wicket:7.0.0:milestone2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B6A90E52-0EF7-4C84-814F-9D6EE832C535"
            },
            {
              "criteria": "cpe:2.3:a:apache:wicket:7.0.0:milestone3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4BC0D445-E39E-472B-8CB9-F363517064CD"
            },
            {
              "criteria": "cpe:2.3:a:apache:wicket:7.0.0:milestone4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F973CD8F-987E-4772-BF35-90076F403796"
            },
            {
              "criteria": "cpe:2.3:a:apache:wicket:7.0.0:milestone5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED3DF7AF-FA68-4DEF-B098-B96510E9ED06"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}