Skip to main content
Version: latest

CVE-2024-38428

CVE Details

CVE-2024-38428

Last Update

8/16/2024

NIST CVE Summary

Url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.

Our Official Summary

Waiting on a fix from third party mongodb vendor.

CVE Severity

9.1

Status

Ongoing

Affected Products & Versions

  • Palette VerteX 4.4.14

Revision History

  • 1.0 08/16/2024 Initial Publication
  • 2.0 08/17/2024 Added Palette VerteX 4.4.14 to Affected Products