Apache Wicket是美国阿帕奇(Apache)基金会的一套开源、轻量、基于组件的框架,它提供了一种面向对象的方式来开发基于Web的动态UI应用程序。 Apache Wicket 8.0.0版本至8.17.0版本、9.0.0版本至9.22.0版本和10.0.0版本至10.8.0版本存在路径遍历漏洞,该漏洞源于FolderUploadsFileManager未验证或清理uploadFieldId参数或clientFileName,可能导致任意文件写入或读取。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Apache Software Foundation | Apache Wicket | 10.0.0≤ 10.8.0 |
affected |
9.0.0≤ 9.22.0 |
affected | ||
8.0.0≤ 8.17 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Wicket | 10.0.0 ~ 10.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-43646 | Apache Wicket: crafted URLs can bypass PackageResourceGuard | |
| CVE-2026-42509 | Apache Wicket: crafted strings can break out of the JavaScript sequence | |
| CVE-2026-40010 | Apache Wicket: possible session fixation using AuthenticatedWebSession |
No comments yet