url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4133-1 wget security update
Ubuntu USN Ubuntu USN USN-6852-1 Wget vulnerability
Ubuntu USN Ubuntu USN USN-6852-2 Wget vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00265}

epss

{'score': 0.00216}


Mon, 21 Apr 2025 19:45:00 +0900

Type Values Removed Values Added
References

Fri, 22 Nov 2024 21:00:00 +0900

Type Values Removed Values Added
References

Tue, 29 Oct 2024 06:15:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:gnu:wget:-:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Sep 2024 22:45:00 +0900

Type Values Removed Values Added
First Time appeared Redhat rhel Eus
CPEs cpe:/a:redhat:enterprise_linux:9
cpe:/a:redhat:rhel_eus:8.8
cpe:/a:redhat:rhel_eus:9.2
Vendors & Products Redhat rhel Eus

Sat, 17 Aug 2024 03:45:00 +0900

Type Values Removed Values Added
First Time appeared Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:8
Vendors & Products Redhat enterprise Linux

Fri, 09 Aug 2024 00:30:00 +0900

Type Values Removed Values Added
First Time appeared Gnu
Gnu wget
Weaknesses CWE-436
CPEs cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu wget
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Wed, 07 Aug 2024 07:45:00 +0900

Type Values Removed Values Added
First Time appeared Redhat
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Tus
CPEs cpe:/a:redhat:rhel_aus:8.6
cpe:/a:redhat:rhel_e4s:8.6
cpe:/a:redhat:rhel_tus:8.6
Vendors & Products Redhat
Redhat rhel Aus
Redhat rhel E4s
Redhat rhel Tus

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-04-21T10:03:18.212Z

Reserved: 2024-06-16T00:00:00.000Z

Link: CVE-2024-38428

cve-icon Vulnrichment

Updated: 2025-04-21T10:03:18.212Z

cve-icon NVD

Status : Modified

Published: 2024-06-16T03:15:08.430

Modified: 2025-04-21T10:15:14.207

Link: CVE-2024-38428

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-06-01T00:00:00Z

Links: CVE-2024-38428 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses