Описание
Weblate: Arbitrary File Read via Symlink
Impact
The ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository.
Patches
References
Thanks to @DavidCarliez for reporting this vulnerability via GitHub.
Пакеты
Наименование
weblate
pip
Затронутые версииВерсия исправления
< 5.17
5.17
Связанные уязвимости
CVSS3: 7.7
nvd
4 месяца назад
Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17.
CVSS3: 7.7
debian
4 месяца назад
Weblate is a web based localization tool. In versions prior to 5.17, t ...