Re: Embedding Wicket Components

2021-05-25 Thread Martin Grigorov
Hi, On Mon, May 24, 2021 at 3:51 AM Ilya Naryzhnyy wrote: > Hello, > > I'm thinking about creating JavaScript library for more seamless embedding > Wicket components and pages into external HTML pages. Use case: there is > Wordpress site and it's needed to embed few components into corresponding

CVE-2021-23937: Apache Wicket: DNS proxy and possible amplification attack

2021-05-25 Thread Emond Papegaaij
Description: A DNS proxy and possible amplification attack vulnerability in WebClientInfo of Apache Wicket allows an attacker to trigger arbitrary DNS lookups from the server when the X-Forwarded-For header is not properly sanitized. This DNS lookup can be engineered to overload an internal DNS se