Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.
History

Tue, 19 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Gnu
Gnu wget
CPEs cpe:2.3:a:gnu:wget:-:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu wget
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 19 Nov 2024 14:45:00 +0000

Type Values Removed Values Added
Description Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.
Title GNU Wget is vulnerable to an SSRF attack when accessing partially-user-controlled shorthand URLs
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: JFROG

Published: 2024-11-19T14:23:09.718Z

Updated: 2024-11-19T15:20:48.148Z

Reserved: 2024-10-30T08:59:30.617Z

Link: CVE-2024-10524

cve-icon Vulnrichment

Updated: 2024-11-19T15:02:56.460Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-19T15:15:06.740

Modified: 2024-11-19T21:57:32.967

Link: CVE-2024-10524

cve-icon Redhat

No data.