Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gcg5-86jr-f7jg

Опубликовано: 07 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Weblate Vulnerable to Private Translation Enumeration via Screenshot API

Impact

The screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user.

Patches

Acknowledgement

Weblate thanks Luay for reporting this vulnerability according to the organization's security issues guideline.

Пакеты

Наименование

weblate

pip
Затронутые версииВерсия исправления

< 5.17.1

5.17.1

EPSS

Процентиль: 21%
0.00288
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-203

Связанные уязвимости

CVSS3: 4.3
nvd
3 месяца назад

Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1.

CVSS3: 4.3
debian
3 месяца назад

Weblate is a web based localization tool. Prior to version 5.17.1, the ...

EPSS

Процентиль: 21%
0.00288
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-203