Triple Critical Threat: Apache Wicket Patch Fixes Path Traversal, Session Hijacking, and Resource Bypass
ID: a063b9b6-a1ab-5493-88a6-6ec85e551d98
STIX ID: report--a063b9b6-a1ab-5493-88a6-6ec85e551d98
Feed Name: securityonline.info
Threat Score
Apache Wicket published an urgent security bulletin reporting four vulnerabilities — three rated Critical (unauthenticated path traversal allowing arbitrary file read/write, session fixation enabling session hijacking, and a PackageResourceGuard bypass) and one Important (cross-site scripting). The advisory affects 8.x, 9.x and 10.x releases and directs users to upgrade to version 10.9.0 immediately to mitigate potential unauthenticated attacks and information disclosure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
