Vulnerability Description
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Wget | <= 1.21.1 |
| Broadcom | Brocade Fabric Operating System Firmware | - |
| Netapp | Cloud Backup | - |
| Netapp | Ontap Select Deploy Administration Utility | - |
| Netapp | A250 Firmware | - |
| Netapp | A250 | - |
| Netapp | 500F Firmware | - |
| Netapp | 500F | - |
Related Weaknesses (CWE)
References
- https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.htmlMailing ListVendor Advisory
- https://security.netapp.com/advisory/ntap-20210618-0002/Third Party Advisory
- https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.htmlMailing ListVendor Advisory
- https://security.netapp.com/advisory/ntap-20210618-0002/Third Party Advisory
FAQ
What is CVE-2021-31879?
CVE-2021-31879 is a vulnerability with a CVSS score of 6.1 (MEDIUM). GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
How severe is CVE-2021-31879?
CVE-2021-31879 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-31879?
Check the references section above for vendor advisories and patch information. Affected products include: Gnu Wget, Broadcom Brocade Fabric Operating System Firmware, Netapp Cloud Backup, Netapp Ontap Select Deploy Administration Utility, Netapp A250 Firmware.