CVE-2018-20483
Last modified
CVE-2018-20483 is a vulnerability of currently unknown severity. set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Wget | < 1.20.1 |
References
- http://git.savannah.gnu.org/cgit/wget.git/tree/NEWSRelease Notes, Third Party Advisory
- http://www.securityfocus.com/bid/106358Third Party Advisory, VDB Entry
- https://security.gentoo.org/glsa/201903-08Third Party Advisory
- https://twitter.com/marcan42/status/1077676739877232640Exploit, Third Party Advisory
- http://git.savannah.gnu.org/cgit/wget.git/tree/NEWSRelease Notes, Third Party Advisory
- http://www.securityfocus.com/bid/106358Third Party Advisory, VDB Entry
- https://security.gentoo.org/glsa/201903-08Third Party Advisory
- https://twitter.com/marcan42/status/1077676739877232640Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20483?
How severe is CVE-2018-20483?
How do I fix CVE-2018-20483?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-20478An issue was discovered in S-CMS 1.0. It allows reading cert…
- CVE-2018-20479An issue was discovered in S-CMS 1.0. It allows SQL Injectio…
- CVE-2018-2048Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-20480An issue was discovered in S-CMS 1.0. It allows SQL Injectio…
- CVE-2018-20481XRef::getEntry in XRef.cc in Poppler 0.72.0 mishandles unall…
- CVE-2018-20482GNU Tar through 1.30, when --sparse is used, mishandles file…4.7
- CVE-2018-20484Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 h…
- CVE-2018-20485Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 h…
- CVE-2018-20486MetInfo 6.x through 6.1.3 has XSS via the /admin/login/login…
- CVE-2018-20487An issue was discovered in the firewall3 component in Inteno…
- CVE-2018-20488An issue was discovered in GitLab Community and Enterprise E…4.3
- CVE-2018-20489An issue was discovered in GitLab Community and Enterprise E…5.3
Are you affected by CVE-2018-20483?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
