PT-2014-2543 · Apache · Apache Wicket

Published

2014-02-10

·

Updated

2014-02-11

·

CVE-2013-2055

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Wicket versions 1.4.x through 1.4.22 Apache Wicket versions 1.5.x through 1.5.10 Apache Wicket versions 6.x through 6.7.x
Description The issue allows remote attackers to obtain sensitive information via vectors that cause raw HTML templates to be rendered without being processed, reading the information outside of wicket:panel markup.
Recommendations For Apache Wicket versions 1.4.x through 1.4.22, update to version 1.4.23 or later. For Apache Wicket versions 1.5.x through 1.5.10, update to version 1.5.11 or later. For Apache Wicket versions 6.x through 6.7.x, update to version 6.8.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2013-2055

Affected Products

Apache Wicket