Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 Maven

Apache Wicket: An attacker can intentionally trigger a memory leak

GHSA-9cxr-76pm-j3wf · CVE-2024-53299

Published · Modified

Description

The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources.
Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue.

Ready to move

Start Securing

Free, no credit card | First findings in minutes