CVE-2020-11976

By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:fortress:2.0.5:*:*:*:*:*:*:*
cpe:2.3:a:apache:wicket:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:wicket:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:wicket:9.0.0:milestone1:*:*:*:*:*:*
cpe:2.3:a:apache:wicket:9.0.0:milestone2:*:*:*:*:*:*
cpe:2.3:a:apache:wicket:9.0.0:milestone3:*:*:*:*:*:*
cpe:2.3:a:apache:wicket:9.0.0:milestone4:*:*:*:*:*:*
cpe:2.3:a:apache:wicket:9.0.0:milestone5:*:*:*:*:*:*

Information

Published : 2020-08-11 12:15

Updated : 2022-04-26 10:06


NVD link : CVE-2020-11976

Mitre link : CVE-2020-11976


JSON object : View

CWE
CWE-552

Files or Directories Accessible to External Parties

Advertisement

dedicated server usa

Products Affected

apache

  • fortress
  • wicket