Applications that use Wget to access a remote resource using shorthand
URLs and pass arbitrary user credentials in the URL are vulnerable. In
these cases attackers can enter crafted credentials which will cause
Wget to access an arbitrary host. (CVE-2024-10524)
- https://bugs.mageia.org/show_bug.cgi?id=33780
- https://www.openwall.com/lists/oss-security/2024/11/18/6
- https://www.cve.org/CVERecord?id=CVE-2024-10524
- 9/core/wget-1.21.4-1.2.mga9
Get the latest Linux and open source security news straight to your inbox.