url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
References
Configurations
History
21 Apr 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
Information
Published : 2024-06-16 03:15
Updated : 2025-04-21 10:15
NVD link : CVE-2024-38428
Mitre link : CVE-2024-38428
CVE.ORG link : CVE-2024-38428
JSON object : View
Products Affected
gnu
- wget
CWE
CWE-436
Interpretation Conflict