Logo
vulnerabilityCVE-2024-10524
Name
CVE-2024-10524
Source
NVD ( link)Debian ( link)
Description
Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
wget
Patched

Vulnerability Ratings#


6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.25.0
Not Affected
buildroot
master
1.25.0
Not Affected
openwrt
master
1.25.0-r4
Not Affected
openwrt
openwrt-25.12
1.25.0-r2
Not Affected
yocto
kirkstone
1.21.4
Patched
yocto
master
1.25.0
Not Affected

Resolved with patches#


wget (yocto:kirkstone)

#
Title
Author
Resolve
1
Fix CVE-2024-10524 (drop support for shorthand URLs)
Tim Rühsen <tim.ruehsen@gmx.de>
CVE-2024-10524

wget (yocto:scarthgap)

#
Title
Author
Resolve
1
Fix CVE-2024-10524 (drop support for shorthand URLs)
Tim Rühsen <tim.ruehsen@gmx.de>
CVE-2024-10524