CVE-2024-53299Uncontrolled Resource Consumption in Apache Wicket

Severity
6.5MEDIUMNVD
EPSS
0.7%
top 27.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 23

Description

The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDapache/wicket9.0.09.19.0+3
CVEListV5apache_software_foundation/apache_wicket7.0.07.18.*+3

🔴Vulnerability Details

3
CVEList
Apache Wicket: An attacker can intentionally trigger a memory leak2025-01-23
OSV
Apache Wicket: An attacker can intentionally trigger a memory leak2025-01-23
GHSA
Apache Wicket: An attacker can intentionally trigger a memory leak2025-01-23
CVE-2024-53299 — Uncontrolled Resource Consumption | cvebase