CVE-2020-11976

HIGH

Apache Wicket <9.0.0-M5 - Info Disclosure

Title source: llm
STIX 2.1

Description

By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5

Scores

CVSS v3 7.5
EPSS 0.0203
EPSS Percentile 84.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-552
Status published
Products (4)
apache/fortress 2.0.5
apache/wicket 9.0.0 milestone1 (5 CPE variants)
apache/wicket < 7.17.0
org.apache.wicket/wicket-core 0 - 7.17.0Maven
Published Aug 11, 2020
Tracked Since Feb 18, 2026