Vulnerability Description
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Fortress | 2.0.5 |
| Apache | Wicket | < 7.17.0 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread.html/r05340178680eb6b9d4d40d56b5621dd4ae9715e6f4
- https://lists.apache.org/thread.html/r104eeefeb1e9da51f7ef79cef0f9ff12e21ef8559bMailing ListRelease NotesVendor Advisory
- https://lists.apache.org/thread.html/r982c626dbce5c995223c4a6ddd7685de3592f8d65b
- https://lists.apache.org/thread.html/rd0f36b83cc9f28b016ec552f023fb5a59a9ea8db56
- https://lists.apache.org/thread.html/rd26cae6e30b205e09e4b511d3d962d4f677c0c604f
- https://lists.apache.org/thread.html/rdec0a43afdca59c10416889e07267f3d2fdf4ab929
- https://lists.apache.org/thread.html/re4af65851bf69605cfb68be215eba36d4cdc1a90b9
- https://lists.apache.org/thread.html/reb7ea8141c713b5b19eaf34c00f43aaebf5a1c1161
- https://lists.apache.org/thread.html/r05340178680eb6b9d4d40d56b5621dd4ae9715e6f4
- https://lists.apache.org/thread.html/r104eeefeb1e9da51f7ef79cef0f9ff12e21ef8559bMailing ListRelease NotesVendor Advisory
- https://lists.apache.org/thread.html/r982c626dbce5c995223c4a6ddd7685de3592f8d65b
- https://lists.apache.org/thread.html/rd0f36b83cc9f28b016ec552f023fb5a59a9ea8db56
- https://lists.apache.org/thread.html/rd26cae6e30b205e09e4b511d3d962d4f677c0c604f
- https://lists.apache.org/thread.html/rdec0a43afdca59c10416889e07267f3d2fdf4ab929
- https://lists.apache.org/thread.html/re4af65851bf69605cfb68be215eba36d4cdc1a90b9
FAQ
What is CVE-2020-11976?
CVE-2020-11976 is a vulnerability with a CVSS score of 7.5 (HIGH). By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually re...
How severe is CVE-2020-11976?
CVE-2020-11976 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11976?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Fortress, Apache Wicket.