Описание
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
Impact
The webhook add-on did not utilize existing SSRF protection.
Patches
Workarounds
Disabling the add-on would avoid misusing this.
References
Thanks to @Lihfdgjr for reporting this via GitHub.
Пакеты
Наименование
Weblate
pip
Затронутые версииВерсия исправления
< 5.17
5.17
Связанные уязвимости
CVSS3: 4.1
nvd
4 месяца назад
Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook add-on as a workaround.
CVSS3: 4.1
debian
4 месяца назад
Weblate is a web based localization tool. In versions prior to 5.17, t ...