CVE-2013-2055
Summary
| CVE | CVE-2013-2055 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-02-10 23:55:04 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that cause raw HTML templates to be rendered without being processed and reading the information that is outside of wicket:panel markup. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS: 0.016270000 probability, percentile 0.819580000 (date 2026-05-04)
Problem Types: NVD-CWE-noinfo | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Wicket | 1.4.0 | All | All | All |
| Application | Apache | Wicket | 1.4.1 | All | All | All |
| Application | Apache | Wicket | 1.4.10 | All | All | All |
| Application | Apache | Wicket | 1.4.11 | All | All | All |
| Application | Apache | Wicket | 1.4.12 | All | All | All |
| Application | Apache | Wicket | 1.4.13 | All | All | All |
| Application | Apache | Wicket | 1.4.14 | All | All | All |
| Application | Apache | Wicket | 1.4.15 | All | All | All |
| Application | Apache | Wicket | 1.4.16 | All | All | All |
| Application | Apache | Wicket | 1.4.17 | All | All | All |
| Application | Apache | Wicket | 1.4.18 | All | All | All |
| Application | Apache | Wicket | 1.4.19 | All | All | All |
| Application | Apache | Wicket | 1.4.20 | All | All | All |
| Application | Apache | Wicket | 1.4.21 | All | All | All |
| Application | Apache | Wicket | 1.4.22 | All | All | All |
| Application | Apache | Wicket | 1.5.0 | All | All | All |
| Application | Apache | Wicket | 1.5.1 | All | All | All |
| Application | Apache | Wicket | 1.5.10 | All | All | All |
| Application | Apache | Wicket | 1.5.2 | All | All | All |
| Application | Apache | Wicket | 1.5.3 | All | All | All |
| Application | Apache | Wicket | 1.5.4 | All | All | All |
| Application | Apache | Wicket | 1.5.5 | All | All | All |
| Application | Apache | Wicket | 1.5.6 | All | All | All |
| Application | Apache | Wicket | 1.5.7 | All | All | All |
| Application | Apache | Wicket | 1.5.8 | All | All | All |
| Application | Apache | Wicket | 1.5.9 | All | All | All |
| Application | Apache | Wicket | 6.1.0 | All | All | All |
| Application | Apache | Wicket | 6.1.1 | All | All | All |
| Application | Apache | Wicket | 6.2.0 | All | All | All |
| Application | Apache | Wicket | 6.3.0 | All | All | All |
| Application | Apache | Wicket | 6.4.0 | All | All | All |
| Application | Apache | Wicket | 6.5.0 | All | All | All |
| Application | Apache | Wicket | 6.6.0 | All | All | All |
| Application | Apache | Wicket | 6.7.0 | All | All | All |
| Application | Apache | Wicket | 6.8.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: [CVE-2013-2055] Apache Wicket information disclosure vulnerability | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | |
| Apache Wicket - Apache Wicket 6.8.0 released | af854a3a-2127-422b-91ae-364da2661108 | wicket.apache.org | Vendor Advisory |
| osvdb.org/102955 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Apache Wicket - CVE-2013-2055 - Apache Wicket Information disclosure vulnerability | af854a3a-2127-422b-91ae-364da2661108 | wicket.apache.org | Vendor Advisory |
| Apache Wicket CVE-2013-2055 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.