CVE-2021-31879
בינונית 6.1
תיאור (מקור, אנגלית)
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - CWE
- CWE-601
מוצרים מושפעים
gnu: wget; broadcom: brocade fabric operating system firmware; netapp: cloud backup; netapp: ontap select deploy administration utility; netapp: a250 firmware; netapp: a250; netapp: 500f firmware; netapp: 500f
קישורים
- https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html Mailing ListVendor Advisory
- https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html Mailing ListVendor Advisory
- https://security.netapp.com/advisory/ntap-20210618-0002/ Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210618-0002/ Third Party Advisory