Description
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
Remediation
References
https://wicket.apache.org/news/2014/09/22/cve-2014-3526.html
Related Vulnerabilities
CVE-2022-33891 Vulnerability in maven package org.apache.spark:spark-core_2.12
CVE-2022-41919 Vulnerability in npm package fastify
CVE-2023-26110 Vulnerability in npm package node-bluetooth
CVE-2017-12160 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2023-34602 Vulnerability in maven package org.jeecgframework.boot:jeecg-boot-base-core