CVE-2021-31879

GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:broadcom:brocade_fabric_operating_system_firmware:-:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:a250:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:netapp:500f_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:500f:-:*:*:*:*:*:*:*

History

13 May 2022, 20:52

Type Values Removed Values Added
CPE cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:500f:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:a250_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:broadcom:brocade_fabric_operating_system_firmware:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
cpe:2.3:o:netapp:500f_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:netapp:a250:-:*:*:*:*:*:*:*
First Time Netapp cloud Backup
Netapp 500f
Netapp a250
Broadcom brocade Fabric Operating System Firmware
Netapp
Netapp 500f Firmware
Netapp a250 Firmware
Netapp ontap Select Deploy Administration Utility
Broadcom
References (CONFIRM) https://security.netapp.com/advisory/ntap-20210618-0002/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20210618-0002/ - Third Party Advisory

18 Jun 2021, 10:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20210618-0002/ -

06 May 2021, 21:24

Type Values Removed Values Added
References (MISC) https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html - (MISC) https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html - Mailing List, Vendor Advisory
CPE cpe:2.3:a:gnu:wget:*:*:*:*:*:*:*:*
CWE CWE-601
CVSS v2 : unknown
v3 : unknown
v2 : 5.8
v3 : 6.1

29 Apr 2021, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-04-29 05:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-31879

Mitre link : CVE-2021-31879

CVE.ORG link : CVE-2021-31879


JSON object : View

Products Affected

netapp

  • ontap_select_deploy_administration_utility
  • a250_firmware
  • cloud_backup
  • a250
  • 500f
  • 500f_firmware

broadcom

  • brocade_fabric_operating_system_firmware

gnu

  • wget
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')