GHSA-9cxr-76pm-j3wf

Suggest an improvement
Source
https://github.com/advisories/GHSA-9cxr-76pm-j3wf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/01/GHSA-9cxr-76pm-j3wf/GHSA-9cxr-76pm-j3wf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9cxr-76pm-j3wf
Aliases
Published
2025-01-23T09:31:17Z
Modified
2025-03-11T16:32:59.120490Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Apache Wicket: An attacker can intentionally trigger a memory leak
Details

The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue.

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2025-01-23T22:31:09Z",
    "nvd_published_at": "2025-01-23T09:15:07Z",
    "cwe_ids": [
        "CWE-400"
    ],
    "severity": "MODERATE"
}
References

Affected packages

Maven / org.apache.wicket:wicket-core

Package

Name
org.apache.wicket:wicket-core
View open source insights on deps.dev
Purl
pkg:maven/org.apache.wicket/wicket-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
8.17.0

Affected versions

7.*

7.0.0
7.1.0
7.2.0
7.3.0
7.4.0
7.5.0
7.6.0
7.7.0
7.8.0
7.9.0
7.10.0
7.11.0
7.12.0
7.13.0
7.14.0
7.15.0
7.16.0
7.17.0
7.18.0

8.*

8.0.0-M1
8.0.0-M2
8.0.0-M3
8.0.0-M4
8.0.0-M5
8.0.0-M6
8.0.0-M7
8.0.0-M8
8.0.0-M9
8.0.0
8.1.0
8.2.0
8.3.0
8.4.0
8.5.0
8.6.0
8.6.1
8.7.0
8.8.0
8.9.0
8.10.0
8.11.0
8.12.0
8.13.0
8.14.0
8.15.0
8.16.0

Maven / org.apache.wicket:wicket-core

Package

Name
org.apache.wicket:wicket-core
View open source insights on deps.dev
Purl
pkg:maven/org.apache.wicket/wicket-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
10.0.0
Fixed
10.3.0

Affected versions

10.*

10.0.0
10.1.0
10.2.0

Maven / org.apache.wicket:wicket-core

Package

Name
org.apache.wicket:wicket-core
View open source insights on deps.dev
Purl
pkg:maven/org.apache.wicket/wicket-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9.0.0-M1
Fixed
9.19.0

Affected versions

9.*

9.0.0-M1
9.0.0-M2
9.0.0-M3
9.0.0-M4
9.0.0-M5
9.0.0
9.1.0
9.2.0
9.3.0
9.4.0
9.5.0
9.6.0
9.7.0
9.8.0
9.9.0
9.9.1
9.10.0
9.11.0
9.12.0
9.13.0
9.14.0
9.15.0
9.16.0
9.17.0
9.18.0