CVE-2021-31879

Public on 2021-04-29
Modified on 2024-01-28
Description
A flaw was found in wget. If wget sends an Authorization header as part of a query and receives an HTTP REDIRECT to a third party in return, the Authorization header will be forwarded as part of the redirected request. This issue creates a password leak, as the second server receives the password. The highest threat from this vulnerability is confidentiality.
Severity
Medium severity
Medium
CVSS v3 Base Score
6.5
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2023 wget 2023-02-17 ALAS2023-2023-012 Fixed
Amazon Linux 2 - Core wget-1.14-18.amzn2 Pending Fix
Amazon Linux 1 wget-1.18-5.30.amzn1 No Fix Planned
Amazon Linux 2023 wget-1.21.2-2.amzn2022 Pending Fix

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
NVD CVSSv2 5.8 AV:N/AC:M/Au:N/C:P/I:P/A:N
NVD CVSSv3 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N