url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | alma-upgrade-wget | Aug 22, 2024 | Jun 16, 2024 | |
| Amazon_linux_2023 | amazon-linux-2023-upgrade-wgetamazon-linux-2023-upgrade-wget-debuginfoamazon-linux-2023-upgrade-wget-debugsource | Feb 17, 2025 | Jun 1, 2024 | |
| Debian | debian-upgrade-wget | Mar 17, 2025 | Jun 16, 2024 | |
| Huawei Euleros 2_0_sp10 | huawei-euleros-2_0_sp10-upgrade-wget | Oct 8, 2024 | Jun 16, 2024 | |
| Huawei Euleros 2_0_sp12 | huawei-euleros-2_0_sp12-upgrade-wget | Oct 9, 2024 | Jun 16, 2024 | |
| Huawei Euleros 2_0_sp8 | huawei-euleros-2_0_sp8-upgrade-wget | Jan 21, 2025 | Jun 16, 2024 | |
| Huawei Euleros 2_0_sp9 | huawei-euleros-2_0_sp9-upgrade-wget | Oct 8, 2024 | Jun 16, 2024 | |
| Oracle_linux | — | oracle-linux-upgrade-wget | Oct 16, 2024 | Jun 1, 2024 |
| Redhat_linux | no-fix-redhat-rpm-packageredhat-upgrade-wgetredhat-upgrade-wget-debuginforedhat-upgrade-wget-debugsource | Sep 6, 2024 | Jun 16, 2024 | |
| Rocky_linux | rocky-upgrade-wgetrocky-upgrade-wget-debuginforocky-upgrade-wget-debugsource | May 8, 2025 | Jun 16, 2024 | |
| Suse | — | suse-upgrade-wgetsuse-upgrade-wget-lang | Jun 24, 2024 | Jun 16, 2024 |
| Ubuntu | ubuntu-pro-upgrade-wgetubuntu-upgrade-wget | Jul 3, 2024 | Jun 16, 2024 | |
| Vmware Photon_os | vmware-photon_os_update_tdnf | Jan 20, 2025 | Jun 16, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub