GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Link | Tags |
---|---|
https://mail.gnu.org/archive/html/bug-wget/2021-02/msg00002.html | mailing list vendor advisory |
https://security.netapp.com/advisory/ntap-20210618-0002/ | third party advisory |