Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3g2f-4rjg-9385

Опубликовано: 14 янв. 2026
Источник: github
Github: Прошло ревью
CVSS4: 2.3

Описание

Weblate leaks information via screenshots

Impact

The screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename.

Patches

References

Thanks to Lukas May and Michael Leu for reporting this.

Пакеты

Наименование

weblate

pip
Затронутые версииВерсия исправления

< 5.15.2

5.15.2

EPSS

Процентиль: 15%
0.00048
Низкий

2.3 Low

CVSS4

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.

CVSS3: 7.5
debian
3 месяца назад

Weblate is a web based localization tool. Prior to 5.15.2, the screens ...

EPSS

Процентиль: 15%
0.00048
Низкий

2.3 Low

CVSS4

Дефекты

CWE-284