CVE-2024-53299

Published Jan 23, 2025

Last updated 23 days ago

Overview

Description
The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recommended to upgrade to versions 9.19.0 or 10.3.0, which fixes this issue.
Source
security@apache.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Severity
MEDIUM

Weaknesses

security@apache.org
CWE-400

Social media

Hype score
Not currently trending
  1. Apache Wicket, the popular Java-based web application framework, has been found vulnerable to a critical security flaw identified as CVE-2024-53299. This vulnerability could allow attackers to intentionally trigger a memory leak, resulting in potential denial-of-service (DoS)… h

    @cybertzar

    27 Jan 2025

    31 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. A critical memory leak vulnerability (CVE-2024-53299) in Apache Wicket exposes web apps to DoS attacks, affecting multiple versions. Users are urged to upgrade to patched versions. 🛡️⚠️ #ApacheWicket #JavaFramework #USA link: https://t.co/r5jjcp3dnV https://t.co/aYS0ffzMfh

    @TweetThreatNews

    27 Jan 2025

    32 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2024-53299 impacts Apache Wicket #ApacheWicket #CVE-2024-53299 https://t.co/OJTS3n7gWV

    @pravin_karthik

    26 Jan 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨🚨Critical Flaw CVE-2024-53299 in Apache Wicket: Memory Leak Flaw Exposes Web Apps to DoS Attacks ⚠️This vulnerability could allow attackers to intentionally trigger a memory leak, resulting in potential denial-of-service (DoS) attacks on affected web applications. ZoomEye… ht

    @zoomeye_team

    26 Jan 2025

    582 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Critical Flaw CVE-2024-53299 in Apache Wicket: Memory Leak Flaw Exposes Web Apps to DoS Attacks Apache Wicket vulnerability alert: CVE-2024-53299. Understand the risk and learn how to secure your web applications against memory leaks. https://t.co/4onbRoc16T

    @the_yellow_fall

    26 Jan 2025

    204 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ☠ Apache Wicket: Un atacante puede provocar intencionadamente una fuga de memoria [CVE-2024-53299] El manejo de peticiones en el núcleo de Apache Wicket 7.0.0 en cuál plataforma permite a un atacante crear un DoS mediante múltiples peticiones al servidor. Actualizar a 9.19.0

    @_Ninhack

    24 Jan 2025

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2024-53299 The request handling in the core in Apache Wicket 7.0.0 on any platform allows an attacker to create a DOS via multiple requests to server resources. Users are recomm… https://t.co/IIEakvYFd6

    @CVEnew

    23 Jan 2025

    398 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2024-53299: Apache Wicket: An attacker can intentionally trigger a memory leak https://t.co/je0evnDSWh

    @oss_security

    22 Jan 2025

    34 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes