{"id":"CVE-2016-6793","details":"The DiskFileItem class in Apache Wicket 6.x before 6.25.0 and 1.5.x before 1.5.17 allows remote attackers to cause a denial of service (infinite loop) and write to, move, and delete files with the permissions of DiskFileItem, and if running on a Java VM before 1.3.1, execute arbitrary code via a crafted serialized Java object.","modified":"2026-07-08T05:49:58.714107241Z","published":"2017-07-17T13:18:06.500Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"apache:wicket","cpes":["cpe:2.3:a:apache:wicket:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.5.0"},{"fixed":"1.5.17"}]}]},"references":[{"type":"ADVISORY","url":"http://www.openwall.com/lists/oss-security/2016/12/31/1"},{"type":"ADVISORY","url":"http://www.securityfocus.com/archive/1/539975/100/0/threaded"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/95168"},{"type":"ADVISORY","url":"http://www.securitytracker.com/id/1037541"},{"type":"ADVISORY","url":"https://wicket.apache.org/news/2016/12/31/cve-2016-6793.html"},{"type":"ADVISORY","url":"https://www.tenable.com/security/research/tra-2016-23"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/wicket","events":[{"introduced":"0d75ee57abb31b4db48c0396870aba39c4d9ddee"},{"fixed":"264ac2f225e5c0183becea936911ce51e001645e"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:apache:wicket:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"6.0.0"},{"fixed":"6.25.0"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6793.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"}]}