There are 2 open security issues in bookworm.
2 issues left for the package maintainer to handle:
- CVE-2021-31879:
(postponed; to be fixed through a stable update)
GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.
- CVE-2024-10524:
(needs triaging)
Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.
You can find information about how to handle these issues in the security team's documentation.