CVE-2020-11976: High severity apache fortress vulnerability
Published Aug 11, 2020
·Updated
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5
Affected Software
8 affected components
Apache Fortress=2.0.5
Apache wicket<7.17.0
Apache wicket>=8.0.0<8.9.0
Apache wicket=9.0.0-milestone1
Apache wicket=9.0.0-milestone2
Apache wicket=9.0.0-milestone3
Apache wicket=9.0.0-milestone4
Apache wicket=9.0.0-milestone5
Remediation
Event History
Aug 11, 2020
CVE Published
via MITRE·06:15 PM
Data Sourced
via MITRE·06:15 PM
DescriptionWeakness