CVE-2024-38428
Last modified
CVE-2024-38428 is a critical-severity vulnerability rated 9.1/10 on the CVSS scale. url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.. EPSS estimates a 0.67% chance of exploitation in the next 30 days.
Description
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Wget | <= 1.24.5 |
References
- https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.htmlMailing List, Patch
- https://lists.gnu.org/archive/html/bug-wget/2024-06/msg00005.htmlMailing List, Patch
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-38428?
How severe is CVE-2024-38428?
How do I fix CVE-2024-38428?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-38422Memory corruption while processing voice packet with arbitra…7.8
- CVE-2024-38423Memory corruption while processing GPU page table switch.7.8
- CVE-2024-38424Memory corruption during GNSS HAL process initialization.7.8
- CVE-2024-38425Information disclosure while sending implicit broadcast cont…6.1
- CVE-2024-38426While processing the authentication message in UE, improper …5.3
- CVE-2024-38427In International Color Consortium DemoIccMAX before 85ce74e,…8.8
- CVE-2024-38429Matrix Tafnit v8 - CWE-552: Files or Directories Accessib…7.5
- CVE-2024-3843Insufficient data validation in Downloads in Google Chrome p…4.3
- CVE-2024-38430Matrix - CWE-79: Improper Neutralization of Input During Web…6.1
- CVE-2024-38431Matrix Tafnit v8 - CWE-204: Observable Response Discrepa…7.5
- CVE-2024-38432Matrix Tafnit v8 - CWE-646: Reliance on File Name or E…9.8
- CVE-2024-38433Nuvoton - CWE-305: Authentication Bypass by Primary Weakness…6.7
Are you affected by CVE-2024-38428?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
