CVE-2024-38428

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*

History

21 Apr 2025, 10:15

Type Values Removed Values Added
References
  • () https://lists.debian.org/debian-lts-announce/2025/04/msg00029.html -

21 Nov 2024, 09:25

Type Values Removed Values Added
References
  • () https://security.netapp.com/advisory/ntap-20241115-0005/ -
References () https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace - Mailing List, Patch () https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace - Mailing List, Patch
References () https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.html - Mailing List, Patch () https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.html - Mailing List, Patch

08 Aug 2024, 15:05

Type Values Removed Values Added
CPE cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*
CWE CWE-436
References () https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace - () https://git.savannah.gnu.org/cgit/wget.git/commit/?id=ed0c7c7e0e8f7298352646b2fd6e06a11e242ace - Mailing List, Patch
References () https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.html - () https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.html - Mailing List, Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Gnu wget
Gnu

17 Jun 2024, 12:42

Type Values Removed Values Added
Summary
  • (es) url.c en GNU Wget hasta 1.24.5 maneja mal los puntos y comas en el subcomponente de información de usuario de un URI y, por lo tanto, puede haber un comportamiento inseguro en el que los datos que se suponía que estaban en el subcomponente de información de usuario se malinterpretan como parte del subcomponente del host.

16 Jun 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-16 03:15

Updated : 2025-04-21 10:15


NVD link : CVE-2024-38428

Mitre link : CVE-2024-38428

CVE.ORG link : CVE-2024-38428


JSON object : View

Products Affected

gnu

  • wget
CWE
CWE-436

Interpretation Conflict