Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.3 Maven

Apache Wicket allows attackers to check for third-party libraries

GHSA-244g-8368-6wr9 · CVE-2014-0043

Published · Modified

Description

In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is in use.

Ready to move

Start Securing

Free, no credit card | First findings in minutes