cbcvebase.
CVE-2024-53299
published 2025-01-23

CVE-2024-53299: The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are…

medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue.

Affected

8 ranges
VendorProductVersion rangeFixed in
apachewicket>= 10.0.0 < 10.3.010.3.0
apachewicket7.0.0 – 7.18.0
apachewicket8.0.0 – 8.16.0
apachewicket>= 9.0.0 < 9.19.09.19.0
apache_software_foundationapache_wicket10.0.0-M1 – 10.2.*
apache_software_foundationapache_wicket7.0.0 – 7.18.*
apache_software_foundationapache_wicket8.0.0-M1 – 8.16.*
apache_software_foundationapache_wicket9.0.0-M1 – 9.18.*