{"id":"GHSA-hmhg-95wh-r699","summary":"DNS based denial of service in Apache Wicket","details":"A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly sanitized. This DNS lookup can be engineered to overload an internal DNS server or to slow down request processing of the Apache Wicket application causing a possible denial of service on either the internal infrastructure or the web application itself. This issue affects Apache Wicket Apache Wicket 9.x version 9.2.0 and prior versions; Apache Wicket 8.x version 8.11.0 and prior versions; Apache Wicket 7.x version 7.17.0 and prior versions and Apache Wicket 6.x version 6.2.0 and later versions.","aliases":["CVE-2021-23937"],"modified":"2023-11-01T04:54:43.997182Z","published":"2022-05-24T19:03:11Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-05-31T18:25:53Z","nvd_published_at":"2021-05-25T17:15:00Z","cwe_ids":["CWE-20"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23937"},{"type":"WEB","url":"https://github.com/apache/wicket/commit/84f62a5cff462eaa3bfaf171b0638c7e7feea30d"},{"type":"PACKAGE","url":"https://github.com/apache/wicket"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r127c0c1f3cb71e5bc619ad1e4b898b97c49758d1f20a54042966473e@%3Cannounce.wicket.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r127c0c1f3cb71e5bc619ad1e4b898b97c49758d1f20a54042966473e@%3Cusers.wicket.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r8ccbd91b56ebf045d151bd4282bfeea7842a0698a0b76118fca8fe78@%3Cdev.wicket.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rc2ef22f90793e158cef65a7e370cdbca023c499d1403d65feeca870d%40%3Cusers.wicket.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rc2ef22f90793e158cef65a7e370cdbca023c499d1403d65feeca870d@%3Cusers.wicket.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rce158bb896c9ef812393a11646fdef7b9023833e54854c4302ff7b70@%3Cdev.wicket.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rce23bba1e11368f9f4cccce0e9b02b88dcdac4e4b2304e66bd098cf5@%3Cannounce.wicket.apache.org%3E"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2021/05/25/2"}],"affected":[{"package":{"name":"org.apache.wicket:wicket-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.wicket/wicket-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"9.0.0"},{"fixed":"9.3.0"}]}],"versions":["9.0.0","9.1.0","9.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hmhg-95wh-r699/GHSA-hmhg-95wh-r699.json"}},{"package":{"name":"org.apache.wicket:wicket-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.wicket/wicket-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.0.0"},{"fixed":"8.12.0"}]}],"versions":["8.0.0","8.1.0","8.10.0","8.11.0","8.2.0","8.3.0","8.4.0","8.5.0","8.6.0","8.6.1","8.7.0","8.8.0","8.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hmhg-95wh-r699/GHSA-hmhg-95wh-r699.json"}},{"package":{"name":"org.apache.wicket:wicket-core","ecosystem":"Maven","purl":"pkg:maven/org.apache.wicket/wicket-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.18.0"}]}],"versions":["1.5-RC1","1.5-RC3","1.5-RC4.2","1.5-RC5.1","1.5-RC7","1.5-rc2","1.5.0","1.5.1","1.5.10","1.5.11","1.5.12","1.5.13","1.5.14","1.5.15","1.5.16","1.5.17","1.5.2","1.5.3","1.5.4","1.5.5","1.5.6","1.5.7","1.5.8","1.5.9","6.0.0","6.0.0-beta1","6.0.0-beta2","6.0.0-beta3","6.1.0","6.1.1","6.10.0","6.11.0","6.12.0","6.13.0","6.14.0","6.15.0","6.16.0","6.17.0","6.18.0","6.19.0","6.2.0","6.20.0","6.21.0","6.22.0","6.23.0","6.24.0","6.25.0","6.26.0","6.27.0","6.27.1","6.28.0","6.29.0","6.3.0","6.30.0","6.4.0","6.5.0","6.6.0","6.7.0","6.8.0","6.9.0","6.9.1","7.0.0","7.0.0-M1","7.0.0-M2","7.0.0-M3","7.0.0-M4","7.0.0-M5","7.0.0-M6","7.1.0","7.10.0","7.11.0","7.12.0","7.13.0","7.14.0","7.15.0","7.16.0","7.17.0","7.2.0","7.3.0","7.4.0","7.5.0","7.6.0","7.7.0","7.8.0","7.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hmhg-95wh-r699/GHSA-hmhg-95wh-r699.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}