Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-31879

Опубликовано: 04 окт. 2019
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.

A flaw was found in wget. If wget sends an Authorization header as part of a query and receives an HTTP REDIRECT to a third party in return, the Authorization header will be forwarded as part of the redirected request. This issue creates a password leak, as the second server receives the password. The highest threat from this vulnerability is confidentiality.

Меры по смягчению последствий

Use --max-redirect 0 when the request contains Authorization header to prevent wget to redirect the request.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6wgetOut of support scope
Red Hat Enterprise Linux 7wgetOut of support scope
Red Hat Enterprise Linux 8wgetAffected
Red Hat Enterprise Linux 9wgetAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1955316wget: authorization header disclosure on redirect

EPSS

Процентиль: 63%
0.01104
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 5 лет назад

GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.

CVSS3: 6.1
nvd
больше 5 лет назад

GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.

CVSS3: 6.1
msrc
больше 5 лет назад

Описание отсутствует

CVSS3: 6.1
debian
больше 5 лет назад

GNU Wget through 1.21.1 does not omit the Authorization header upon a ...

suse-cvrf
больше 1 года назад

Security update for wget

EPSS

Процентиль: 63%
0.01104
Низкий

6.5 Medium

CVSS3