CVE-2024-38428

ADVISORY - nist

Summary

url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

EPSS Score: 0.00197 (0.415)

Common Weakness Enumeration (CWE)

ADVISORY - nist

Interpretation Conflict

ADVISORY - redhat

Misinterpretation of Input


Sign in to Docker Scout

See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.

Sign in