CVE-2024-10524
CVE-2024-10524
Título es
CVE-2024-10524
Mar, 19/11/2024 – 15:15
Tipo
CWE-918
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-10524
Descripción en
Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.
19/11/2024
19/11/2024
Vector CVSS:3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
Gravedad 3.1 (CVSS 3.1 Base Score)
6.50
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
Enviar en el boletín
Off