CVE-2024-38428

CRITICAL

GNU Wget <1.24.5 - Info Disclosure

Title source: llm
STIX 2.1

Description

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

Scores

CVSS v3 9.1
EPSS 0.0020
EPSS Percentile 41.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-436
Status published
Products (1)
gnu/wget < 1.24.5
Published Jun 16, 2024
Tracked Since Feb 18, 2026