CVE-2020-11976: Apache Fortress

High severity, CVSS 7.5. EPSS: 3.8% chance of exploitation in the next 30 days.

By crafting a special URL it is possible to make Wicket deliver unprocessed HTML templates. This would allow an attacker to see possibly sensitive information inside a HTML template that is usually removed during rendering. Affected are Apache Wicket versions 7.16.0, 8.8.0 and 9.0.0-M5

Affected products

  • Apache Fortress: version 2.0.5 only
  • Apache Wicket: before 7.17.0 (fixed in 7.17.0); from 8.0.0, before 8.9.0 (fixed in 8.9.0); version 9.0.0 only

Published 2020-08-11. Last modified 2026-06-17.