https://seclists.org/oss-sec/2024/q3/58: CVE-2024-36522: Apache Wicket: mote code execution via XSLT injection
Published Jul 12, 2024
·Updated
Affected Software
3 affected components
Apache wicket>=10.0.0-M1<=10.0.0
Apache wicket>=9.0.0<9.17.0
Apache wicket>=8.0.0<8.15.0
Frequently Asked Questions
1
What is the severity of CVE-2024-36522?
The severity of CVE-2024-36522 is moderate.
2
Which versions of Apache Wicket are affected by CVE-2024-36522?
CVE-2024-36522 affects Apache Wicket versions 10.0.0-M1 through 10.0.0, 9.0.0 through 9.17.0, and 8.0.0 through 8.15.0.
3
What type of vulnerability is CVE-2024-36522?
CVE-2024-36522 is a remote code execution vulnerability caused by XSLT injection.
4
How do I fix CVE-2024-36522?
To fix CVE-2024-36522, upgrade to a non-vulnerable version of Apache Wicket.
5
What are the risks associated with CVE-2024-36522?
The risks associated with CVE-2024-36522 include potential remote code execution if exploited by an attacker.