#VU53532 Input validation error in Apache Wicket - CVE-2021-23937
Published: May 25, 2021
Apache Wicket
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in WebClientInfo when processing the "X-Forwarded-For" HTTP header. A remote attacker can force the server to initiate numerous DNS lookups and overload the internal DNS server.