vulnerability

Amazon Linux 2023: CVE-2021-31879: Medium priority package update for wget

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
Oct 4, 2019
Added
Feb 17, 2025
Modified
Feb 17, 2025

Description

GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
A flaw was found in wget. If wget sends an Authorization header as part of a query and receives an HTTP REDIRECT to a third party in return, the Authorization header will be forwarded as part of the redirected request. This issue creates a password leak, as the second server receives the password. The highest threat from this vulnerability is confidentiality.

Solutions

amazon-linux-2023-upgrade-wgetamazon-linux-2023-upgrade-wget-debuginfoamazon-linux-2023-upgrade-wget-debugsource
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.