Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Bachir Bendrissou

#27938of 53,635
9.1Total CVSS
Vulnerabilities · 1
PT-2024-4197
9.1
2024-06-01
Gnu · Gnu Wget · CVE-2024-38428
**Name of the Vulnerable Software and Affected Versions** GNU Wget versions 1.24.5 and earlier **Description** The issue is related to the userinfo URI component manager in GNU Wget, where data intended for the userinfo subcomponent is misinterpreted as part of the host subcomponent due to insecure behavior when handling semicolons. This could allow a remote attacker to impact the confidentiality and integrity of protected information. **Recommendations** For GNU Wget versions 1.24.5 and earlier, consider updating to a version later than 1.24.5 to resolve the issue. As a temporary workaround, avoid using semicolons in the userinfo subcomponent of a URI until a patch is available. Restrict access to sensitive information that could be impacted by this issue until the update is applied.