QID 982028
QID 982028: Java (maven) Security Update for org.apache.wicket:wicket-core (GHSA-64gv-3pqv-299h)
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-64gv-3pqv-299h for updates pertaining to this vulnerability.
Vendor References
- GHSA-64gv-3pqv-299h -
github.com/advisories/GHSA-64gv-3pqv-299h
CVEs related to QID 982028
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-64gv-3pqv-299h | org.apache.wicket:wicket-core |
|