CVE-2014-7808: Apache Wicket
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Apache Wicket before 1.5.13, 6.x before 6.19.0, and 7.x before 7.0.0-M5 make it easier for attackers to defeat a cryptographic protection mechanism and predict encrypted URLs by leveraging use of CryptoMapper as the default encryption provider.
Affected products
- Apache Wicket: from 1.5.0, before 1.5.13 (fixed in 1.5.13); from 6.0.0, before 6.19.0 (fixed in 6.19.0); version 7.0.0 only
Published 2017-09-15. Last modified 2026-06-17.