Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gr35-vpx2-qxhc

Опубликовано: 05 нояб. 2025
Источник: github
Github: Прошло ревью
CVSS3: 2.6

Описание

Weblate leaks the IP of project member inviting user to be reviewer in Audit log

Summary

Weblate leaks the IP address of the project member inviting the user to the project in the audit log.

Details

The audit log included IP addresses from admin-triggered actions, and those could be viewed by invited users.

Impact

The inviting user's (admin's) IP address could be leaked to invited users.

Пакеты

Наименование

weblate

pip
Затронутые версииВерсия исправления

< 5.14.1

5.14.1

EPSS

Процентиль: 9%
0.00031
Низкий

2.6 Low

CVSS3

Дефекты

CWE-212

Связанные уязвимости

CVSS3: 2.6
nvd
3 месяца назад

Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.

CVSS3: 2.6
debian
3 месяца назад

Weblate is a web based localization tool. In versions 5.14 and below, ...

EPSS

Процентиль: 9%
0.00031
Низкий

2.6 Low

CVSS3

Дефекты

CWE-212