PT-2024-8827 · Wget+4 · Wget+4

Goni Golan

·

Published

2024-10-27

·

Updated

2026-04-15

·

CVE-2024-10524

CVSS v3.1

6.5

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Wget versions prior to 1.25.0
Description: The issue is related to insufficient validation of requests on the server side, allowing attackers to exploit Wget's shorthand URL handling. This can lead to Server-Side Request Forgery (SSRF) attacks, phishing attacks, or Man-in-the-Middle (MiTM) attacks. Applications that use Wget to access remote resources using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. Attackers can enter crafted credentials, causing Wget to access an arbitrary host.
Recommendations: For versions prior to 1.25.0, update to Wget 1.25.0 or later to mitigate the risk. As a temporary workaround, consider sanitizing inputs and avoiding the use of shorthand URLs. Restrict access to vulnerable modules or functions to minimize the risk of exploitation.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-15537
AZL-53235
BDU:2024-10463
CVE-2024-10524
ECHO-DFE7-A7ED-8A10
JLSEC-2026-119
MGASA-2024-0378
OESA-2024-2497
OPENSUSE-SU-2024:14492-1
OPENSUSE-SU-2024_4138-1
OPENSUSE-SU-2024_4145-1
SUSE-SU-2024:4138-1
SUSE-SU-2024:4145-1
SUSE-SU-2024_4138-1
SUSE-SU-2024_4145-1
SUSE-SU-2025:01921-1
SUSE-SU-2025:20097-1
SUSE-SU-2025:20325-1
SUSE-SU-2025_01921-1

Affected Products

Alt Linux
Debian
Red Os
Suse
Wget