First published: Thu Apr 29 2021(Updated: )
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU Wget | <=1.21.1 | |
Broadcom Brocade Fabric Operating System Firmware | ||
Netapp Cloud Backup | ||
NetApp ONTAP Select Deploy administration utility | ||
Netapp A250 Firmware | ||
Netapp A250 | ||
Netapp 500f Firmware | ||
Netapp 500f |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31879 is a vulnerability in GNU Wget through 1.21.1 that does not omit the Authorization header upon a redirect to a different origin.
CVE-2021-31879 has a severity rating of medium with a CVSS score of 6.1.
GNU Wget through 1.21.1, Broadcom Brocade Fabric Operating System Firmware, Netapp Cloud Backup, NetApp ONTAP Select Deploy administration utility, Netapp A250 Firmware, and Netapp 500f Firmware are affected by CVE-2021-31879.
Update GNU Wget to version 1.21.2 or later to fix CVE-2021-31879.
Yes, you can find references for CVE-2021-31879 at the following links: [Reference 1](https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html) and [Reference 2](https://security.netapp.com/advisory/ntap-20210618-0002/).