CVE-2024-53299: Apache Wicket: An attacker can intentionally trigger a memory leak
Published Jan 22, 2025
·Updated
The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue.
Affected Software
8 affected componentsFixes available
Apache wicket<9.19.0, <10.3.0
maven/org.apache.wicket:wicket-core>=9.0.0-M1<9.19.0
9.19.0
maven/org.apache.wicket:wicket-core>=7.0.0<8.17.0
8.17.0
maven/org.apache.wicket:wicket-core>=10.0.0<10.3.0
10.3.0
Apache wicket>=7.0.0<=7.18.0
Apache wicket>=8.0.0<=8.16.0
Apache wicket>=9.0.0<9.19.0
Apache wicket>=10.0.0<10.3.0
Event History
Jan 23, 2025
CVE Published
via MITRE·08:37 AM
Data Sourced
via MITRE·08:37 AM
DescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
Affected Software
Advisory Published
via GitHub·09:31 AM
Frequently Asked Questions
1
What is the severity of CVE-2024-53299?
CVE-2024-53299 has been categorized as a denial-of-service vulnerability.
2
How do I fix CVE-2024-53299?
To fix CVE-2024-53299, upgrade Apache Wicket to version 9.19.0 or 10.3.0.
3
What systems are affected by CVE-2024-53299?
CVE-2024-53299 affects Apache Wicket versions prior to 9.19.0 and between 7.0.0 and 10.3.0.
4
What type of attack does CVE-2024-53299 enable?
CVE-2024-53299 allows attackers to perform denial-of-service attacks by sending multiple requests to server resources.
5
Is CVE-2024-53299 a critical vulnerability?
CVE-2024-53299 is considered serious as it can disrupt service availability.