Vulnerabilities > GNU > Wget > 1.20.1

DATE CVE VULNERABILITY TITLE RISK
2024-06-16 CVE-2024-38428 Interpretation Conflict vulnerability in GNU Wget
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
network
low complexity
gnu CWE-436
critical
9.1
2021-04-29 CVE-2021-31879 Open Redirect vulnerability in multiple products
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
network
low complexity
gnu broadcom netapp CWE-601
6.1