Impact
This vulnerability allows an attacker to craft URLs that bypass Apache Wicket's PackageResourceGuard, leading to the exposure of sensitive application resources. The flaw is a case of insufficient input validation that permits unauthorized access to protected files, classified as CWE-200. An attacker could gain read access to files or resources that should be restricted, compromising confidentiality and potentially enabling further exploitation.
Affected Systems
The affected product is Apache Wicket, distributed by the Apache Software Foundation. Versions from 8.0.0 through 8.17.0, from 9.0.0 through 9.22.0, and from 10.0.0 through 10.8.0 are vulnerable. Users are advised to upgrade to version 10.9.0 or later, which contains the fix for this issue.
Risk and Exploitability
EPSS score is < 1%, indicating a very low likelihood of public exploitation and the vulnerability is not listed on CISA's KEV catalog. Nevertheless, the CVSS score is 7.5, classifying the vulnerability as high severity and suggesting that the ability to read restricted resources poses a moderate to high risk to confidentiality. The attack can be carried out remotely by sending a crafted URL to a vulnerable Wicket application, without any authentication. Consequently, organizations running the affected versions should treat this as a priority patching issue.
OpenCVE Enrichment
Github GHSA