Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
wget2 Improper Certificate Validation
Vulnerability Description
wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
输入验证不恰当
Vulnerability Title
wget2 输入验证错误漏洞
Vulnerability Description
wget2是美国GNU社区的一个支持高性能并发下载与现代协议特性的网络文件获取工具。 wget2存在输入验证错误漏洞,该漏洞源于接受具有不正确密钥用途或扩展密钥用途的服务器证书,可能允许攻击者重用为不同目的颁发的证书进行TLS服务器身份验证。
CVSS Information
N/A
Vulnerability Type
N/A