← Back

CVE-2020-11976

nvd nist
Published: Aug 11, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5

Affected (8)

Products: Apache: Fortress, Wicket
2 products
Fortress
Wicket
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.0.5
Apache
Before 7.17.0
From 8.0.0 to 8.9.0
Version 9.0.0 milestone1
Version 9.0.0 milestone2
Version 9.0.0 milestone3
Version 9.0.0 milestone4
Version 9.0.0 milestone5

References (16)

Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListRelease NotesVendor Advisory

Timeline

No history available yet.