Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-57jg-m997-cx3q

Опубликовано: 16 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

Weblate lacks rate limiting when verifying second factor

Impact

The verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing.

Patches

This issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918.

References

Thanks to obscuredeer for reporting this issue at HackerOne.

Пакеты

Наименование

weblate

pip
Затронутые версииВерсия исправления

< 5.12

5.12

EPSS

Процентиль: 13%
0.00044
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 4.9
nvd
8 месяцев назад

Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12.

CVSS3: 4.9
debian
8 месяцев назад

Weblate is a web based localization tool. Prior to version 5.12, the v ...

EPSS

Процентиль: 13%
0.00044
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-307