Apache Wicket
cpe:2.3:a:apache:wicket:*:*:*:*:*:*:*
- >= 7.0.0, <= 7.18.*
- >= 8.0.0-M1, <= 8.16.*
- >= 9.0.0-M1, <= 9.18.*
- >= 10.0.0-M1, <= 10.2.*
A denial-of-service vulnerability has been identified in Apache Wicket versions 7.0.0 through 7.18.*, 8.0.0-M1 through 8.16.*, 9.0.0-M1 through 9.18.*, and 10.0.0-M1 through 10.2.*. The issue arises in the core request handling, where an attacker can cause a memory leak by sending multiple requests to server resources, leading to a denial-of-service condition.
Exploitation of this vulnerability causes a memory leak, which can lead to a denial-of-service condition by exhausting server resources.
Users are advised to upgrade to Apache Wicket versions 9.19.0 or 10.3.0, which address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.