Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-38428

Опубликовано: 16 июн. 2024
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 9.1

Описание

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

РелизСтатусПримечание
devel

released

1.24.5-1ubuntu2
esm-infra-legacy/trusty

needs-triage

esm-infra/bionic

released

1.19.4-1ubuntu2.2+esm1
esm-infra/focal

not-affected

1.20.3-1ubuntu2.1
esm-infra/xenial

released

1.17.1-1ubuntu1.5+esm1
focal

released

1.20.3-1ubuntu2.1
jammy

released

1.21.2-2ubuntu1.1
mantic

released

1.21.3-1ubuntu1.1
noble

released

1.21.4-1ubuntu4.1
oracular

released

1.24.5-1ubuntu2

Показывать по

EPSS

Процентиль: 50%
0.00265
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 5.5
redhat
около 1 года назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

CVSS3: 9.1
nvd
около 1 года назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

CVSS3: 9.1
msrc
12 месяцев назад

Описание отсутствует

CVSS3: 9.1
debian
около 1 года назад

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo ...

suse-cvrf
12 месяцев назад

Security update for wget

EPSS

Процентиль: 50%
0.00265
Низкий

9.1 Critical

CVSS3

Уязвимость CVE-2024-38428