Server-side Request Forgery (SSRF) Affecting wget package, versions [,1.25.0)
Threat Intelligence
Exploit Maturity
Proof of concept
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-UNMANAGED-WGET-8384363
- published 19 Nov 2024
- disclosed 19 Nov 2024
- credit Goni Golan
Introduced: 19 Nov 2024
New CVE-2024-10524 Open this link in a new tabHow to fix?
Upgrade wget
to version 1.25.0 or higher.
Overview
Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the handling of shorthand URLs that include user credentials. An attacker can manipulate the URL to cause the server to connect to an arbitrary host by crafting malicious credentials.