Описание
In Apache Wicket 1.5.10 or 6.13.0, by issuing requests to special urls handled by Wicket, it is possible to check for the existence of particular classes in the classpath and thus check whether a third party library with a known security vulnerability is in use.
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:apache:wicket:1.5.10:*:*:*:*:*:*:*
cpe:2.3:a:apache:wicket:6.13.0:*:*:*:*:*:*:*
EPSS
Процентиль: 73%
0.00786
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
Связанные уязвимости
CVSS3: 5.3
github
около 3 лет назад
Apache Wicket allows attackers to check for third-party libraries
EPSS
Процентиль: 73%
0.00786
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200