CVE-2020-11976
11.08.2020, 19:15
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5Enginsight
Vendor | Product | Version |
---|---|---|
apache | fortress | 2.0.5 |
apache | wicket | 𝑥 < 7.17.0 |
apache | wicket | 8.0.0 ≤ 𝑥 < 8.9.0 |
apache | wicket | 9.0.0:milestone1 |
apache | wicket | 9.0.0:milestone2 |
apache | wicket | 9.0.0:milestone3 |
apache | wicket | 9.0.0:milestone4 |
apache | wicket | 9.0.0:milestone5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References