GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-wget | Mar 21, 2024 | Apr 29, 2021 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-wgetamazon-linux-2023-upgrade-wget-debuginfoamazon-linux-2023-upgrade-wget-debugsource | Feb 17, 2025 | Oct 4, 2019 | |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Apr 29, 2021 | |
| Debian | no-fix-debian-deb-package | May 15, 2025 | Apr 29, 2021 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Apr 29, 2021 |
| Ubuntu | no-fix-ubuntu-package | Jun 26, 2025 | Apr 29, 2021 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Apr 29, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub