https://seclists.org/oss-sec/2025/q1/56: CVE-2024-53299: Apache Wicket: An attacker can intentionally trigger a memory leak
Published Jan 22, 2025
·Updated
Affected Software
4 affected components
Apache wicket>=7.0.0<7.19.0
Apache wicket>=8.0.0-M1<8.17.0
Apache wicket>=9.0.0-M1<9.19.0
Apache wicket>=10.0.0-M1<10.3.0
Frequently Asked Questions
1
What is the severity of CVE-2024-53299?
The severity of CVE-2024-53299 is rated as critical.
2
Which versions of Apache Wicket are affected by CVE-2024-53299?
CVE-2024-53299 affects Apache Wicket versions 7.0.0 through 7.18.*, 8.0.0-M1 through 8.16.*, 9.0.0-M1 through 9.18.*, and 10.0.0-M1 through 10.2.*.
3
How do I fix CVE-2024-53299?
To fix CVE-2024-53299, upgrade to the latest version of Apache Wicket that is not affected by this vulnerability.
4
What type of vulnerability is CVE-2024-53299?
CVE-2024-53299 is a memory leak vulnerability in the request handling core of Apache Wicket.
5
Can CVE-2024-53299 affect application performance?
Yes, CVE-2024-53299 can lead to increased resource consumption and degrade application performance.