Apache Wicket allows attackers to check for third-party libraries
Moderate severity
GitHub Reviewed
Published
May 17, 2022
to the GitHub Advisory Database
•
Updated Apr 23, 2025
Package
Affected versions
>= 1.5-RC1, <= 1.5.10
>= 6.0.0-beta1, <= 6.13.0
Patched versions
1.5.11
6.14.0
Description
Published by the National Vulnerability Database
Oct 3, 2017
Published to the GitHub Advisory Database
May 17, 2022
Reviewed
Apr 23, 2025
Last updated
Apr 23, 2025
In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is in use.
References