Critical severity9.8NVD Advisory· Published Jul 12, 2024· Updated Jun 17, 2026
CVE-2024-36522
CVE-2024-36522
Description
The default configuration of XSLTResourceStream.java is vulnerable to remote code execution via XSLT injection when processing input from an untrusted source without validation. Users are recommended to upgrade to versions 10.1.0, 9.18.0 or 8.16.0, which fix this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.wicket:wicket-utilMaven | >= 10.0.0-M1, < 10.1.0 | 10.1.0 |
org.apache.wicket:wicket-utilMaven | >= 9.0.0, < 9.18.0 | 9.18.0 |
org.apache.wicket:wicket-utilMaven | >= 8.0.0, < 8.16.0 | 8.16.0 |
Affected products
5- Apache Software Foundation/Apache Wicketv5Range: 10.0.0-M1
Patches
Vulnerability mechanics
References
4- www.openwall.com/lists/oss-security/2024/07/12/2nvdMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-hhwc-gh8h-9rrpghsaADVISORY
- lists.apache.org/thread/w613qh7yors840pbx00l1pq6wkl9jzkcnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-36522ghsaADVISORY
News mentions
0No linked articles in our index yet.