Описание
Apache Wicket: An attacker can intentionally trigger a memory leak
The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue.
Пакеты
org.apache.wicket:wicket-core
>= 7.0.0, < 8.17.0
8.17.0
org.apache.wicket:wicket-core
>= 10.0.0, < 10.3.0
10.3.0
org.apache.wicket:wicket-core
>= 9.0.0-M1, < 9.19.0
9.19.0
Связанные уязвимости
The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue.
Уязвимость компонента Request Handler фреймворка для создания веб-приложений на языке Java Apache Wicket, позволяющая нарушителю вызвать отказ в обслуживании