QID 355217
Date Published: 2023-05-29
QID 355217: Amazon Linux Security Advisory for wget : ALAS2023-2023-012
A flaw was found in wget.
If wget sends an authorization header as part of a query and receives an http redirect to a third party in return, the authorization header will be forwarded as part of the redirected request.
This issue creates a password leak, as the second server receives the password.
The highest threat from this vulnerability is confidentiality. (
( CVE-2021-31879)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
Solution
Please refer to Amazon advisory: ALAS2023-2023-012 for affected packages and patching details, or update with your package manager.
Vendor References
- ALAS2023-2023-012 -
alas.aws.amazon.com/AL2023/ALAS-2023-012.html
CVEs related to QID 355217
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2023-2023-012 | amazon linux 2023 |
|