First published: Tue Aug 11 2020(Updated: )
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Fortress | =2.0.5 | |
Apache Wicket | <7.17.0 | |
Apache Wicket | >=8.0.0<8.9.0 | |
Apache Wicket | =9.0.0-milestone1 | |
Apache Wicket | =9.0.0-milestone2 | |
Apache Wicket | =9.0.0-milestone3 | |
Apache Wicket | =9.0.0-milestone4 | |
Apache Wicket | =9.0.0-milestone5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.