CVE-2014-0043: Infoleak
In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is in use.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0043?
CVE-2014-0043 has a medium severity rating as it allows for the identification of vulnerable third-party libraries.
How do I fix CVE-2014-0043?
To fix CVE-2014-0043, update Apache Wicket to version 1.5.11 or 6.13.1 or later.
What systems are affected by CVE-2014-0043?
CVE-2014-0043 affects Apache Wicket versions 1.5.10 and 6.13.0.
Can CVE-2014-0043 lead to unauthorized access?
While CVE-2014-0043 does not directly grant unauthorized access, it exposes the existence of vulnerable classes, potentially leading to further exploitation.
Is CVE-2014-0043 a local or remote vulnerability?
CVE-2014-0043 is considered a remote vulnerability as it can be exploited through specially crafted URLs.