← Back

CVE-2024-38428

nvd nist
Published: Jun 16, 2024Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

Affected (1)

Products: Gnu: Wget
1 product
Wget
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.24.5

References (6)

Timeline

No history available yet.