Lucene search

K
nvd[email protected]NVD:CVE-2024-38428
HistoryJun 16, 2024 - 3:15 a.m.

CVE-2024-38428

2024-06-1603:15:08
web.nvd.nist.gov
7
gnu wget
1.24.5
url
userinfo subcomponent
insecure behavior

0.0004 Low

EPSS

Percentile

9.2%

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.