CRITICAL 9.1 Microsoft
CVE-2024-38428
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
Microsoft Security Update 2024-Jun: url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
Affected Products
- cbl2 wget 1.21.2-3 on CBL Mariner 2.0
- cbl2 wget 1.21.2-4 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38428
- https://nvd.nist.gov/vuln/detail/CVE-2024-38428
This critical severity vulnerability with a CVSS score of 9.1 was published on 2024-06-11 via Microsoft. Affected: cbl2 wget 1.21.2-3 on CBL Mariner 2.0, cbl2 wget 1.21.2-4 on CBL Mariner 2.0.
Risk Timeline
CVE Disclosed2024-06-11 · 827 days ago
Remediation Resources
Official Advisory
msrc.microsoft.com/update-guide/vulnerability/CVE-2024-38428NVD / MITRE
nvd.nist.gov/vuln/detail/CVE-2024-38428Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2025-49844 PoC | Redis Lua Use-After-Free may lead to remote code execution | CRITICAL | 9.9 |
| CVE-2024-41110 PoC | Moby authz zero length regression | CRITICAL | 9.9 |
| CVE-2024-24790 | Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netip | CRITICAL | 9.8 |
| CVE-2024-39331 | In Emacs before 29.4 org-link-expand-abbrev in lisp/ol.el expands a %(...) link | CRITICAL | 9.8 |
| CVE-2024-4577 PoC | Argument Injection in PHP-CGI | CRITICAL | 9.8 |
| CVE-2024-38541 | of: module: add buffer overflow check in of_modalias() | CRITICAL | 9.8 |
vulnfeed aggregates 8294 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.