GHSA-hmhg-95wh-r699
HIGHCVE-2021-23937A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly sanitized. This DNS lookup can be engineered to overload an internal DNS server or to slow down request processing of the Apache Wicket application causing a possible denial of service on ei
- Affected
- >= 9.0.0, < 9.3.0, < 7.18.0, >= 8.0.0, < 8.12.0
- Fixed in
- 9.3.0
- Weakness
- CWE-20
- Published
- 2022-05-24
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference