CVE-2018-20483
Summary
| CVE | CVE-2018-20483 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-12-26 18:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2018-20483 GNU Wget Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| GNU wget CVE-2018-20483 Local Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| GNU Wget: Password and metadata leak (GLSA 201903-08) — Gentoo security | GENTOO | security.gentoo.org | Third Party Advisory |
| USN-3943-1: Wget vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| NEWS - wget.git - GNU Wget | MISC | git.savannah.gnu.org | Release Notes, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Hector Martin auf Twitter: "So yeah, um, this is not okay. It is not discoverable and could easily leak sensitive information. Auth credentials even, seriously? Also Chrome does this too. And it is preserved across `mv` to another filesystem.… https://t.co/y8Cq1feOol" | MISC | twitter.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.