Description
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
Remediation
References
https://wicket.apache.org/news/2014/09/22/cve-2014-3526.html
Related Vulnerabilities
CVE-2021-4133 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2023-26134 Vulnerability in npm package git-commit-info
CVE-2019-1003072 Vulnerability in maven package org.jenkins-ci.plugins:wildfly-deployer
CVE-2023-34453 Vulnerability in maven package org.xerial.snappy:snappy-java
CVE-2019-1003069 Vulnerability in maven package org.jenkins-ci.plugins:aqua-security-scanner