In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is in use.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2017-10-02T13:00:00Z
Updated: 2024-09-16T19:56:10.491Z
Reserved: 2013-12-03T00:00:00
Link: CVE-2014-0043
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-10-03T01:29:00.327
Modified: 2024-11-21T02:01:14.283
Link: CVE-2014-0043
Redhat
No data.