By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5
Advisories
Source ID Title
EUVD EUVD EUVD-2021-0965 By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5
Github GHSA Github GHSA GHSA-64gv-3pqv-299h Exposure of Sensitive Information to an Unauthorized Actor in Apache Wicket
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-04T11:48:57.562Z

Reserved: 2020-04-21T00:00:00

Link: CVE-2020-11976

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-08-11T19:15:17.220

Modified: 2024-11-21T04:59:01.770

Link: CVE-2020-11976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.