Vulnerability Description
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Wicket | >= 1.5.0, < 1.5.12 |
Related Weaknesses (CWE)
References
- https://wicket.apache.org/news/2014/09/22/cve-2014-3526.htmlIssue TrackingThird Party Advisory
- https://wicket.apache.org/news/2014/09/22/cve-2014-3526.htmlIssue TrackingThird Party Advisory
FAQ
What is CVE-2014-3526?
CVE-2014-3526 is a vulnerability with a CVSS score of 7.5 (HIGH). Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for tempo...
How severe is CVE-2014-3526?
CVE-2014-3526 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-3526?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Wicket.