{"id":"CVE-2020-11976","aliases":["GHSA-64gv-3pqv-299h"],"url":"https://o3.security/vulnerability/CVE-2020-11976","summary":"Exposure of Sensitive Information to an Unauthorized Actor in Apache Wicket","details":"By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5","published":"2020-08-11T19:15:17.220Z","modified":"2026-07-08T05:55:18.447608970Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.03759,"percentile":0.89339,"asOf":"2026-09-16"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.wicket:wicket-core","fixedVersion":"7.17.0"},{"ecosystem":"Maven","name":"org.apache.wicket:wicket-core","fixedVersion":"8.9.0"},{"ecosystem":"Maven","name":"org.apache.wicket:wicket-core","fixedVersion":"9.0.0"},{"ecosystem":"Maven","name":"org.apache.wicket:wicket-core","fixedVersion":"9.0.0"},{"ecosystem":"Maven","name":"org.apache.wicket:wicket-core","fixedVersion":"9.0.0"},{"ecosystem":"Maven","name":"org.apache.wicket:wicket-core","fixedVersion":"9.0.0"},{"ecosystem":"Maven","name":"org.apache.wicket:wicket-core","fixedVersion":"9.0.0"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/r05340178680eb6b9d4d40d56b5621dd4ae9715e6f41f12ae2288ec49%40%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r982c626dbce5c995223c4a6ddd7685de3592f8d65ba8372da1f3ce19%40%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rd0f36b83cc9f28b016ec552f023fb5a59a9ea8db56f2b9dcc6a2f6b7%40%3Ccommits.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rd26cae6e30b205e09e4b511d3d962d4f677c0c604f737997ce1b2f22%40%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rdec0a43afdca59c10416889e07267f3d2fdf4ab929a6e22a2659b6ff%40%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/re4af65851bf69605cfb68be215eba36d4cdc1a90b95fbc894799d923%40%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/reb7ea8141c713b5b19eaf34c00f43aaebf5a1c116130f763c42bdad1%40%3Cdev.directory.apache.org%3E"},{"type":"ADVISORY","url":"https://lists.apache.org/thread.html/r104eeefeb1e9da51f7ef79cef0f9ff12e21ef8559b77801e86b21e16%40%3Cusers.wicket.apache.org%3E"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-11976"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r05340178680eb6b9d4d40d56b5621dd4ae9715e6f41f12ae2288ec49@%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/r982c626dbce5c995223c4a6ddd7685de3592f8d65ba8372da1f3ce19@%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rd0f36b83cc9f28b016ec552f023fb5a59a9ea8db56f2b9dcc6a2f6b7@%3Ccommits.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rd26cae6e30b205e09e4b511d3d962d4f677c0c604f737997ce1b2f22@%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/rdec0a43afdca59c10416889e07267f3d2fdf4ab929a6e22a2659b6ff@%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/re4af65851bf69605cfb68be215eba36d4cdc1a90b95fbc894799d923@%3Cdev.directory.apache.org%3E"},{"type":"WEB","url":"https://lists.apache.org/thread.html/reb7ea8141c713b5b19eaf34c00f43aaebf5a1c116130f763c42bdad1@%3Cdev.directory.apache.org%3E"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:55:18.447608970Z"}}