Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mpf5-3vph-q75r

Опубликовано: 16 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Weblate: Improper access control for the translation memory in API

Impact

The translation memory API exposed unintended endpoints, which in turn didn't do proper access control.

Patches

Workarounds

Blocking access to /api/memory/ in the HTTP server removes access to this feature.

References

This issue was reported by ggamno via HackerOne.

Пакеты

Наименование

Weblate

pip
Затронутые версииВерсия исправления

< 5.17

5.17

EPSS

Процентиль: 15%
0.00236
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 4.3
nvd
4 месяца назад

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't enforce proper access control. This issue has been fixed in version 5.17. If users are unable to update immediately, they can work around this issue by blocking access to /api/memory/ in the HTTP server, which removes access to this feature.

CVSS3: 4.3
debian
4 месяца назад

Weblate is a web based localization tool. In versions prior to 5.17, t ...

EPSS

Процентиль: 15%
0.00236
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-862