Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
2017-10-30T14:29:00.500
2025-04-20T01:37:25.860
Deferred
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | apache | wicket | < 1.5.12 | Yes |
Application | apache | wicket | 6.0.0 | Yes |
Application | apache | wicket | 6.0.0 | Yes |
Application | apache | wicket | 6.0.0 | Yes |
Application | apache | wicket | 6.0.0 | Yes |
Application | apache | wicket | 6.1.0 | Yes |
Application | apache | wicket | 6.1.1 | Yes |
Application | apache | wicket | 6.2.0 | Yes |
Application | apache | wicket | 6.3.0 | Yes |
Application | apache | wicket | 6.4.0 | Yes |
Application | apache | wicket | 6.5.0 | Yes |
Application | apache | wicket | 6.6.0 | Yes |
Application | apache | wicket | 6.7.0 | Yes |
Application | apache | wicket | 6.8.0 | Yes |
Application | apache | wicket | 6.9.0 | Yes |
Application | apache | wicket | 6.9.1 | Yes |
Application | apache | wicket | 6.10.0 | Yes |
Application | apache | wicket | 6.11.0 | Yes |
Application | apache | wicket | 6.12.0 | Yes |
Application | apache | wicket | 6.13.0 | Yes |
Application | apache | wicket | 6.14.0 | Yes |
Application | apache | wicket | 6.15.0 | Yes |
Application | apache | wicket | 6.16.0 | Yes |
Application | apache | wicket | 7.0.0 | Yes |
Application | apache | wicket | 7.0.0 | Yes |
Application | apache | wicket | 7.0.0 | Yes |