← Back

CVE-2014-3526

nvd nist
Published: Oct 30, 2017Modified: May 13, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.

Affected (26)

Products: Apache: Wicket
1 product
Wicket
Configuration A
26 vulnerable
Vulnerable SoftwareAffected Versions
Apache
From 1.5.0 to 1.5.12
Version 6.0.0
Version 6.0.0 beta1
Version 6.0.0 beta2
Version 6.0.0 beta3
Version 6.1.0
Version 6.1.1
Version 6.10.0
Version 6.11.0
Version 6.12.0
Version 6.13.0
Version 6.14.0
Version 6.15.0
Version 6.16.0
Version 6.2.0
Version 6.3.0
Version 6.4.0
Version 6.5.0
Version 6.6.0
Version 6.7.0
Version 6.8.0
Version 6.9.0
Version 6.9.1
Version 7.0.0
Version 7.0.0 milestone1
Version 7.0.0 milestone2

References (2)

Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory

Timeline

No history available yet.