First published: Fri Jul 14 2017(Updated: )
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Wicket | >=1.5.0<1.5.17 | |
Apache Wicket | >=6.0.0<6.25.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-6793 is considered a high severity vulnerability due to its potential for denial of service and arbitrary code execution.
To fix CVE-2016-6793, upgrade to Apache Wicket version 6.25.0 or higher, or 1.5.17 or higher.
CVE-2016-6793 affects Apache Wicket versions 1.5.0 through 1.5.16 and 6.0.0 through 6.24.0.
The potential impacts of CVE-2016-6793 include denial of service due to an infinite loop and unauthorized file operations with the permissions of DiskFileItem.
There is no documented workaround for CVE-2016-6793; the recommended action is to upgrade to a fixed version.