First published: Mon Oct 30 2017(Updated: )
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.wicket:wicket-core | >=7.0.0-M1<7.0.0-M3 | 7.0.0-M3 |
maven/org.apache.wicket:wicket-core | >=6.0<6.17.0 | 6.17.0 |
maven/org.apache.wicket:wicket-core | <1.5.12 | 1.5.12 |
Apache Wicket | >=1.5.0<1.5.12 | |
Apache Wicket | =6.0.0 | |
Apache Wicket | =6.0.0-beta1 | |
Apache Wicket | =6.0.0-beta2 | |
Apache Wicket | =6.0.0-beta3 | |
Apache Wicket | =6.1.0 | |
Apache Wicket | =6.1.1 | |
Apache Wicket | =6.2.0 | |
Apache Wicket | =6.3.0 | |
Apache Wicket | =6.4.0 | |
Apache Wicket | =6.5.0 | |
Apache Wicket | =6.6.0 | |
Apache Wicket | =6.7.0 | |
Apache Wicket | =6.8.0 | |
Apache Wicket | =6.9.0 | |
Apache Wicket | =6.9.1 | |
Apache Wicket | =6.10.0 | |
Apache Wicket | =6.11.0 | |
Apache Wicket | =6.12.0 | |
Apache Wicket | =6.13.0 | |
Apache Wicket | =6.14.0 | |
Apache Wicket | =6.15.0 | |
Apache Wicket | =6.16.0 | |
Apache Wicket | =7.0.0 | |
Apache Wicket | =7.0.0-milestone1 | |
Apache Wicket | =7.0.0-milestone2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.