← Back to CVE List

CVE-2020-11976

Published: 2020-08-11T19:15Z
Last Modified: 2024-11-21T04:59Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5 > MITRE Terms of Use apply – see LICENSE‑MITRE.txt