Описание
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
A flaw was found in wget. If wget sends an Authorization header as part of a query and receives an HTTP REDIRECT to a third party in return, the Authorization header will be forwarded as part of the redirected request. This issue creates a password leak, as the second server receives the password. The highest threat from this vulnerability is confidentiality.
Меры по смягчению последствий
Use --max-redirect 0 when the request contains Authorization header to prevent wget to redirect the request.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | wget | Out of support scope | ||
| Red Hat Enterprise Linux 7 | wget | Out of support scope | ||
| Red Hat Enterprise Linux 8 | wget | Affected | ||
| Red Hat Enterprise Linux 9 | wget | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
GNU Wget through 1.21.1 does not omit the Authorization header upon a ...
EPSS
6.5 Medium
CVSS3