yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2024-10524
Component Overview
Vulnerability Overview
Name
CVE-2024-10524
Source
NVD (
link
)
Debian (
link
)
Description
Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.
CWEs
CWE-918
Published Date
Nov 19, 2024
Updated Date
Jun 17, 2026
Workaround
-
Advisories
Analysis
#
Affected Component
Analysis
wget
Patched
Vulnerability Ratings
#
6.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
wget
buildroot
2025.02.x
1.25.0
Not Affected
wget
buildroot
master
1.25.0
Not Affected
wget
openwrt
master
1.25.0-r4
Not Affected
wget
openwrt
openwrt-25.12
1.25.0-r2
Not Affected
wget
yocto
kirkstone
1.21.4
Patched
wget
yocto
master
1.25.0
Not Affected
Resolved with patches
#
wget (yocto:kirkstone)
#
Title
Author
Resolve
1
Fix CVE-2024-10524 (drop support for shorthand URLs)
Tim Rühsen <tim.ruehsen@gmx.de>
CVE-2024-10524
wget (yocto:scarthgap)
#
Title
Author
Resolve
1
Fix CVE-2024-10524 (drop support for shorthand URLs)
Tim Rühsen <tim.ruehsen@gmx.de>
CVE-2024-10524