{"api_version":"1","generated_at":"2026-04-23T01:43:01+00:00","cve":"CVE-2018-20483","urls":{"html":"https://cve.report/CVE-2018-20483","api":"https://cve.report/api/cve/CVE-2018-20483.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-20483","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-20483"},"summary":{"title":"CVE-2018-20483","description":"set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2018-12-26 18:29:00","updated_at":"2020-08-24 17:37:00"},"problem_types":["CWE-200"],"metrics":[],"references":[{"url":"https://security.netapp.com/advisory/ntap-20190321-0002/","name":"https://security.netapp.com/advisory/ntap-20190321-0002/","refsource":"CONFIRM","tags":[],"title":"CVE-2018-20483 GNU Wget Vulnerability in NetApp Products | NetApp Product Security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/106358","name":"106358","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"GNU wget CVE-2018-20483 Local Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://security.gentoo.org/glsa/201903-08","name":"GLSA-201903-08","refsource":"GENTOO","tags":["Third Party Advisory"],"title":"GNU Wget: Password and metadata leak (GLSA 201903-08) — Gentoo security","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://usn.ubuntu.com/3943-1/","name":"USN-3943-1","refsource":"UBUNTU","tags":[],"title":"USN-3943-1: Wget vulnerabilities | Ubuntu security notices","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.savannah.gnu.org/cgit/wget.git/tree/NEWS","name":"http://git.savannah.gnu.org/cgit/wget.git/tree/NEWS","refsource":"MISC","tags":["Release Notes","Third Party Advisory"],"title":"NEWS - wget.git - GNU Wget","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2019:3701","name":"RHSA-2019:3701","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://twitter.com/marcan42/status/1077676739877232640","name":"https://twitter.com/marcan42/status/1077676739877232640","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Hector Martin auf Twitter: \"So yeah, um, this is not okay. It is not discoverable and could easily leak sensitive information. Auth credentials even, seriously?\n\nAlso Chrome does this too. And it is preserved across `mv` to another filesystem.… https://t.co/y8Cq1feOol\"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-20483","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-20483","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"20483","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnu","cpe5":"wget","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"20483","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnu","cpe5":"wget","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2018-20483","qid":"296080","title":"Oracle Solaris 11.4 Support Repository Update (SRU) 13.4.0 Missing (CPUJUL2019)"},{"cve":"CVE-2018-20483","qid":"500737","title":"Alpine Linux Security Update for wget"},{"cve":"CVE-2018-20483","qid":"504513","title":"Alpine Linux Security Update for wget"},{"cve":"CVE-2018-20483","qid":"710191","title":"Gentoo Linux GNU Wget Password and metadata leak Vulnerability (GLSA 201903-08)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2018-20483","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"GLSA-201903-08","refsource":"GENTOO","url":"https://security.gentoo.org/glsa/201903-08"},{"name":"106358","refsource":"BID","url":"http://www.securityfocus.com/bid/106358"},{"name":"https://twitter.com/marcan42/status/1077676739877232640","refsource":"MISC","url":"https://twitter.com/marcan42/status/1077676739877232640"},{"name":"http://git.savannah.gnu.org/cgit/wget.git/tree/NEWS","refsource":"MISC","url":"http://git.savannah.gnu.org/cgit/wget.git/tree/NEWS"},{"refsource":"CONFIRM","name":"https://security.netapp.com/advisory/ntap-20190321-0002/","url":"https://security.netapp.com/advisory/ntap-20190321-0002/"},{"refsource":"UBUNTU","name":"USN-3943-1","url":"https://usn.ubuntu.com/3943-1/"},{"refsource":"REDHAT","name":"RHSA-2019:3701","url":"https://access.redhat.com/errata/RHSA-2019:3701"}]}},"nvd":{"publishedDate":"2018-12-26 18:29:00","lastModifiedDate":"2020-08-24 17:37:00","problem_types":["CWE-200"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":2.1},"severity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*","versionEndExcluding":"1.20.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"20483","Ordinal":"140831","Title":"CVE-2018-20483","CVE":"CVE-2018-20483","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"20483","Ordinal":"1","NoteData":"set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"20483","Ordinal":"2","NoteData":"2018-12-26","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"20483","Ordinal":"3","NoteData":"2019-11-05","Type":"Other","Title":"Modified"}]}}}