First published: Fri Jul 14 2017(Updated: )
The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Wicket | >=1.5.0<1.5.17 | |
Apache Wicket | >=6.0.0<6.25.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.