CVE-2018-20483

set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
Affected Products (NVD)
VendorProductVersion
gnuwget
𝑥
< 1.20.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
wget
bookworm
1.21.3-1
fixed
bullseye
1.21-1+deb11u1
fixed
jessie
not-affected
sid
1.24.5-2
fixed
stretch
not-affected
trixie
1.24.5-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
wget
bionic
Fixed 1.19.4-1ubuntu2.2
released
cosmic
Fixed 1.19.5-1ubuntu1.1
released
trusty
not-affected
xenial
not-affected
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
curl
RHEL 8
0:7.61.1-11.el8
fixed
libcurl
RHEL 8
0:7.61.1-11.el8
fixed
libcurl-devel
RHEL 8
0:7.61.1-11.el8
fixed
libcurl-minimal
RHEL 8
0:7.61.1-11.el8
fixed