Vulnerability Details CVE-2024-53299
The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources.
Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 56.1%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2024-53299
-
cpe:2.3:a:apache:wicket:10.0.0
-
cpe:2.3:a:apache:wicket:10.1.0
-
cpe:2.3:a:apache:wicket:10.2.0
-
cpe:2.3:a:apache:wicket:7.0.0
-
cpe:2.3:a:apache:wicket:7.1.0
-
cpe:2.3:a:apache:wicket:7.10.0
-
cpe:2.3:a:apache:wicket:7.11.0
-
cpe:2.3:a:apache:wicket:7.12.0
-
cpe:2.3:a:apache:wicket:7.13.0
-
cpe:2.3:a:apache:wicket:7.14.0
-
cpe:2.3:a:apache:wicket:7.16.0
-
cpe:2.3:a:apache:wicket:7.17.0
-
cpe:2.3:a:apache:wicket:7.18.0
-
cpe:2.3:a:apache:wicket:7.2.0
-
cpe:2.3:a:apache:wicket:7.3.0
-
cpe:2.3:a:apache:wicket:7.4.0
-
cpe:2.3:a:apache:wicket:7.5.0
-
cpe:2.3:a:apache:wicket:7.6.0
-
cpe:2.3:a:apache:wicket:7.7.0
-
cpe:2.3:a:apache:wicket:7.8.0
-
cpe:2.3:a:apache:wicket:7.9.0
-
cpe:2.3:a:apache:wicket:8.0.0
-
cpe:2.3:a:apache:wicket:8.1.0
-
cpe:2.3:a:apache:wicket:8.10.0
-
cpe:2.3:a:apache:wicket:8.11.0
-
cpe:2.3:a:apache:wicket:8.12.0
-
cpe:2.3:a:apache:wicket:8.13.0
-
cpe:2.3:a:apache:wicket:8.14.0
-
cpe:2.3:a:apache:wicket:8.15.0
-
cpe:2.3:a:apache:wicket:8.16.0
-
cpe:2.3:a:apache:wicket:8.2.0
-
cpe:2.3:a:apache:wicket:8.3.0
-
cpe:2.3:a:apache:wicket:8.4.0
-
cpe:2.3:a:apache:wicket:8.5.0
-
cpe:2.3:a:apache:wicket:8.6.0
-
cpe:2.3:a:apache:wicket:8.6.1
-
cpe:2.3:a:apache:wicket:8.7.0
-
cpe:2.3:a:apache:wicket:8.8.0
-
cpe:2.3:a:apache:wicket:8.9.0
-
cpe:2.3:a:apache:wicket:9.0.0
-
cpe:2.3:a:apache:wicket:9.1.0
-
cpe:2.3:a:apache:wicket:9.10.0
-
cpe:2.3:a:apache:wicket:9.11.0
-
cpe:2.3:a:apache:wicket:9.12.0
-
cpe:2.3:a:apache:wicket:9.13.0
-
cpe:2.3:a:apache:wicket:9.14.0
-
cpe:2.3:a:apache:wicket:9.15.0
-
cpe:2.3:a:apache:wicket:9.16.0
-
cpe:2.3:a:apache:wicket:9.17.0
-
cpe:2.3:a:apache:wicket:9.18.0
-
cpe:2.3:a:apache:wicket:9.2.0
-
cpe:2.3:a:apache:wicket:9.3.0
-
cpe:2.3:a:apache:wicket:9.4.0
-
cpe:2.3:a:apache:wicket:9.5.0
-
cpe:2.3:a:apache:wicket:9.6.0
-
cpe:2.3:a:apache:wicket:9.7.0
-
cpe:2.3:a:apache:wicket:9.8.0
-
cpe:2.3:a:apache:wicket:9.9.0
-
cpe:2.3:a:apache:wicket:9.9.1