Information disclosure in wget - CVE-2021-31879
Published: February 6, 2025
Vulnerability identifier: #VU103688
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-31879
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the application does not omit the Authorization header upon a redirect to a different origin. A remote attacker can gain access to credentials for another domain.
Affected software
wget
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
Basesystem Module
openSUSE Leap
Rapid Infrastructure Automation
APEX Cloud Platform for Microsoft Azure
watsonx.data
SmartFabric Manager
wget-debuginfo
wget
wget-debugsource
wget-lang
APEX Cloud Platform for Red Hat OpenShift
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
Amazon Linux AMI
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
Basesystem Module
openSUSE Leap
Rapid Infrastructure Automation
APEX Cloud Platform for Microsoft Azure
watsonx.data
SmartFabric Manager
wget-debuginfo
wget
wget-debugsource
wget-lang
APEX Cloud Platform for Red Hat OpenShift
How to mitigate CVE-2021-31879
Install updates from vendor's website.
wget - update to 1.21.2
Rapid Infrastructure Automation - update to 1.1.5.3
watsonx.data - update to 2.2
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
wget-debuginfo - addressed in versions 1.14-21.22.1, 1.20.3-150000.3.29.1, 1.20.3-150600.19.12.1
wget - addressed in versions 1.14-21.22.1, 1.20.3-150000.3.29.1, 1.20.3-150600.19.12.1
wget-debugsource - addressed in versions 1.14-21.22.1, 1.20.3-150000.3.29.1, 1.20.3-150600.19.12.1
wget-lang - update to 1.20.3-150600.19.12.1
wget - update to 1.21.3-1
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
Rapid Infrastructure Automation - update to 1.1.5.3
watsonx.data - update to 2.2
SmartFabric Manager - update to 1.3.0
APEX Cloud Platform for Microsoft Azure - update to 01.04.01.00
wget-debuginfo - addressed in versions 1.14-21.22.1, 1.20.3-150000.3.29.1, 1.20.3-150600.19.12.1
wget - addressed in versions 1.14-21.22.1, 1.20.3-150000.3.29.1, 1.20.3-150600.19.12.1
wget-debugsource - addressed in versions 1.14-21.22.1, 1.20.3-150000.3.29.1, 1.20.3-150600.19.12.1
wget-lang - update to 1.20.3-150600.19.12.1
wget - update to 1.21.3-1
APEX Cloud Platform for Red Hat OpenShift - update to 03.02.04.00
External References
Related Security Bulletins
- Information disclosure in GNU Wget
- SUSE update for wget
- SUSE update for wget
- SUSE update for wget
- Amazon Linux AMI update for wget
- Dell APEX Cloud Platform for Red Hat OpenShift update for third-party components
- Dell APEX Cloud Platform for Microsoft Azure update for third-party components
- Multiple vulnerabilities in IBM Rapid Infrastructure Automation
- Dell SmartFabric Manager update for third-party components
- Multiple vulnerabilities in IBM watsonx.data