Description
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.
Remediation
References
https://wicket.apache.org/news/2014/09/22/cve-2014-3526.html
Related Vulnerabilities
CVE-2022-21144 Vulnerability in npm package libxmljs
CVE-2023-33510 Vulnerability in maven package org.jeecgframework.p3:jeecg-p3-biz-chat
CVE-2022-26260 Vulnerability in npm package simple-plist
CVE-2020-5206 Vulnerability in maven package org.opencastproject:opencast-kernel
CVE-2018-11694 Vulnerability in maven package org.webjars.npm:node-sass