Problemunvalidated
stores the full download URL including embedded credentials in POSIX extended file attributes — Wget's extended file attribute feature (--xattr flag). Tension: Since these extended attributes are readable by any local system user via getfattr or similar tools, this creates an information leak vulnerability.
387874e7-37b5-4a18-a967-86d63a08ff1a
stores the full download URL including embedded credentials in POSIX extended file attributes — Wget's extended file attribute feature (--xattr flag). Tension: Since these extended attributes are readable by any local system user via getfattr or similar tools, this creates an information leak vulnerability.