Back to search
CVE-2024-36522
Published: Jul 12, 2024
Modified: Feb 13, 2025
PUBLISHED
Description
The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untrusted source without validation. Users are recommended to upgrade to versions 10.1.0, 9.18.0 or 8.16.0, which fix this issue.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Wicket | affected 10.0.0-M1 - <= 10.0.0affected 9.0.0 - <= 9.17.0affected 8.0.0 - <= 8.15.0 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now