CVE-2014-3526: Infoleak
Published Oct 30, 2017
·Updated
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
Affected Software
29 affected componentsFixes available
maven/org.apache.wicket:wicket-core>=7.0.0-M1<7.0.0-M3
7.0.0-M3
maven/org.apache.wicket:wicket-core>=6.0<6.17.0
6.17.0
maven/org.apache.wicket:wicket-core<1.5.12
1.5.12
Apache wicket>=1.5.0<1.5.12
Apache wicket=6.0.0
Apache wicket=6.0.0-beta1
Apache wicket=6.0.0-beta2
Apache wicket=6.0.0-beta3
Apache wicket=6.1.0
Apache wicket=6.1.1
Apache wicket=6.2.0
Apache wicket=6.3.0
Apache wicket=6.4.0
Apache wicket=6.5.0
Apache wicket=6.6.0
Apache wicket=6.7.0
Apache wicket=6.8.0
Apache wicket=6.9.0
Apache wicket=6.9.1
Apache wicket=6.10.0
Apache wicket=6.11.0
Apache wicket=6.12.0
Apache wicket=6.13.0
Apache wicket=6.14.0
Apache wicket=6.15.0
Apache wicket=6.16.0
Apache wicket=7.0.0
Apache wicket=7.0.0-milestone1
Apache wicket=7.0.0-milestone2
Event History
Oct 30, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
May 13, 2022
Advisory Published
01:30 AM
Frequently Asked Questions
1
What is the severity of CVE-2014-3526?
CVE-2014-3526 is classified as a medium severity vulnerability.
2
How do I fix CVE-2014-3526?
To fix CVE-2014-3526, upgrade to Apache Wicket versions 1.5.12, 6.17.0, or 7.0.0-M3 or later.
3
What kind of information can be leaked by CVE-2014-3526?
CVE-2014-3526 may allow remote attackers to obtain sensitive information related to user session page markup.
4
Which versions of Apache Wicket are affected by CVE-2014-3526?
CVE-2014-3526 affects Apache Wicket versions prior to 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3.
5
Is there a risk of exploitation for CVE-2014-3526?
Yes, CVE-2014-3526 poses a risk as it could potentially allow an attacker to exploit session data.