Lucene search

K
vulnrichmentMitreVULNRICHMENT:CVE-2024-38428
HistoryJun 16, 2024 - 12:00 a.m.

CVE-2024-38428

2024-06-1600:00:00
mitre
github.com
4
url.c
semicolons
uri
userinfo
insecure behavior
host subcomponent

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

35.6%

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

35.6%

SSVC

Exploitation

none

Automatable

no

Technical Impact

partial