[CVE-2012-3373] Apache Wicket XSS vulnerability via manipulated URL parameter

2012-09-06 Thread Carl-Eric Menzel
Severity: Important

Vendor:
The Apache Software Foundation

Versions Affected:
Apache Wicket 1.4.x and 1.5.x

Description:
https://wicket.apache.org/2012/09/06/cve-2012-3373.html
It is possible to inject JavaScript statements into an ajax link by
adding an encoded null byte to a URL pointing to a Wicket app. This
could be done by sending a legitimate user a manipulated URL and
tricking the user into clicking on it.

This vulnerability is fixed in
- Apache Wicket 1.4.21
  https://wicket.apache.org/2012/09/05/wicket-1.4.21-released.html
- Apache Wicket 1.5.8
  https://wicket.apache.org/2012/08/24/wicket-1.5.8-released.html

Apache Wicket 6.0.0 is not affected.

Credit:
This issue was reported by Thomas Heigl.

Apache Wicket Team


Re: Apache Wicket 6 in the news

2012-09-06 Thread Andrea Del Bene

Good work indeed! You have done an impressive job promoting this release!

Thanks to the awesome support of press@ (THX Sally!) we have some
great coverage of our 6.0 release:

ASF Bowls Apache Wicket 6.0 At Open Sourcers
http://www.techweekeurope.co.uk/news/asf-apache-wicket-6-0-91604

Hitting it for six — Wicket reaches 6.0, learns some new tricks
http://jaxenter.com/wicket-reaches-6-0-learns-some-new-tricks-44332.html

Apache Wicket 6.0 Java Web App Framework Launches
http://www.eweek.com/c/a/Application-Development/Apache-Wicket-60-Java-Web-App-Framework-Launches-374537/

Wicket 6.0 Brings Out of The Box JQuery And More
http://java.dzone.com/articles/wicket-60-brings-out-box

My favorite coverage 'til now (author did a real good job researching
our project, including the version bump that was not part of the
release notes):

Apache Wicket bounces to a 6
http://www.h-online.com/open/news/item/Apache-Wicket-bounces-to-a-6-1699707.html

On twitter:
Pour un Framework Web vieillissant, il se porte plutôt bien: #Wicket
sort en v6.0
Apache #Wicket 6.0.0 has moved to JQuery. Now to see how much trouble
it is as a server-side solution for Curl markup
Wicket 6 is out! t.co/glBbVkBy. Some very neat improvements! #wicket
-- J'en connais qui vont être content
Wicket 6 is out! t.co/j5CYM1XL. Some very neat improvements! #wicket
#wicket 6 is out in the wild, natives celebrate worldwide.. \O/
Wicket 6 と 1.4.21 が同時リリースか… “@ivaynberg: #wicket 6.0.0 announcement
now live on the project page: wicket.apache.org”