CVE-2020-11976

By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
apacheCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 82%
VendorProductVersion
apachefortress
2.0.5
apachewicket
𝑥
< 7.17.0
apachewicket
8.0.0 ≤
𝑥
< 8.9.0
apachewicket
9.0.0:milestone1
apachewicket
9.0.0:milestone2
apachewicket
9.0.0:milestone3
apachewicket
9.0.0:milestone4
apachewicket
9.0.0:milestone5
𝑥
= Vulnerable software versions
References