Описание
Weblate command-line client susceptible to SSL verification skip
Impact
The SSL verification would be skipped for some crafted URLs.
Patches
Workarounds
Avoid using untrusted wlc configurations, as that might cause insecure connections.
References
This issue was reported to us by wh1zee via HackerOne.
Пакеты
Наименование
wlc
pip
Затронутые версииВерсия исправления
< 1.17.0
1.17.0
Связанные уязвимости
CVSS3: 2.5
ubuntu
27 дней назад
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.
CVSS3: 2.5
nvd
27 дней назад
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.
CVSS3: 2.5
debian
27 дней назад
wlc is a Weblate command-line client using Weblate's REST API. Prior t ...