Vulnerability Details CVE-2024-38428
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 49.9%
CVSS Severity
CVSS v3 Score 9.1
Products affected by CVE-2024-38428
-
-
-
cpe:2.3:a:gnu:wget:1.10.1
-
cpe:2.3:a:gnu:wget:1.10.2
-
-
cpe:2.3:a:gnu:wget:1.11.1
-
cpe:2.3:a:gnu:wget:1.11.2
-
cpe:2.3:a:gnu:wget:1.11.3
-
cpe:2.3:a:gnu:wget:1.11.4
-
cpe:2.3:a:gnu:wget:1.11.4-1
-
-
-
cpe:2.3:a:gnu:wget:1.13.1
-
cpe:2.3:a:gnu:wget:1.13.3
-
cpe:2.3:a:gnu:wget:1.13.4
-
-
-
-
cpe:2.3:a:gnu:wget:1.16.1
-
cpe:2.3:a:gnu:wget:1.16.2
-
cpe:2.3:a:gnu:wget:1.16.3
-
-
cpe:2.3:a:gnu:wget:1.17.1
-
-
-
cpe:2.3:a:gnu:wget:1.19.1
-
cpe:2.3:a:gnu:wget:1.19.2
-
cpe:2.3:a:gnu:wget:1.19.3
-
cpe:2.3:a:gnu:wget:1.19.4
-
cpe:2.3:a:gnu:wget:1.19.5
-
-
cpe:2.3:a:gnu:wget:1.20.1
-
-
-
-
-
-
-
-
-
-
-
-
-
-