{"id":"CVE-2020-11976","details":"By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5","aliases":["GHSA-64gv-3pqv-299h"],"modified":"2026-07-08T05:55:18.447608970Z","published":"2020-08-11T19:15:17.220Z","database_specific":{"unresolved_ranges":[{"vendor_product":"apache:fortress","cpes":["cpe:2.3:a:apache:fortress:2.0.5:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.0.5"},{"last_affected":"2.0.5"}],"source":"CPE_STRING"}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r05340178680eb6b9d4d40d56b5621dd4ae9715e6f41f12ae2288ec49%40%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r982c626dbce5c995223c4a6ddd7685de3592f8d65ba8372da1f3ce19%40%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rd0f36b83cc9f28b016ec552f023fb5a59a9ea8db56f2b9dcc6a2f6b7%40%3Ccommits.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rd26cae6e30b205e09e4b511d3d962d4f677c0c604f737997ce1b2f22%40%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rdec0a43afdca59c10416889e07267f3d2fdf4ab929a6e22a2659b6ff%40%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/re4af65851bf69605cfb68be215eba36d4cdc1a90b95fbc894799d923%40%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/reb7ea8141c713b5b19eaf34c00f43aaebf5a1c116130f763c42bdad1%40%3Cdev.directory.apache.org%3E"},{"type":"ADVISORY","url":"https://lists.apache.org/thread.html/r104eeefeb1e9da51f7ef79cef0f9ff12e21ef8559b77801e86b21e16%40%3Cusers.wicket.apache.org%3E"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/wicket","events":[{"introduced":"0"},{"fixed":"2d92f60565fc0c5d5954ce6f313555b596197d6d"},{"introduced":"5e789f1c98f6d57dba17f896c6220b0202af08a9"},{"fixed":"c16442d69a2120a1d7453211bcffd68f56b629d7"},{"introduced":"f911c636696a85fb1b81bdf1319667733c3e69fb"},{"last_affected":"e66ea49163d48852d17435954cc6a61277339553"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:apache:wicket:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:wicket:9.0.0:milestone1:*:*:*:*:*:*","cpe:2.3:a:apache:wicket:9.0.0:milestone2:*:*:*:*:*:*","cpe:2.3:a:apache:wicket:9.0.0:milestone3:*:*:*:*:*:*","cpe:2.3:a:apache:wicket:9.0.0:milestone4:*:*:*:*:*:*","cpe:2.3:a:apache:wicket:9.0.0:milestone5:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"7.17.0"},{"introduced":"8.0.0"},{"fixed":"8.9.0"},{"introduced":"9.0.0-milestone1"},{"last_affected":"9.0.0-milestone1"},{"introduced":"9.0.0-milestone2"},{"last_affected":"9.0.0-milestone2"},{"introduced":"9.0.0-milestone3"},{"last_affected":"9.0.0-milestone3"},{"introduced":"9.0.0-milestone4"},{"last_affected":"9.0.0-milestone4"},{"introduced":"9.0.0-milestone5"},{"last_affected":"9.0.0-milestone5"}]}}],"versions":["9.0.0-milestone1","9.0.0-milestone2","9.0.0-milestone3","9.0.0-milestone4","9.0.0-milestone5","rel/wicket-9.0.0-M5"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-11976.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}