Описание
The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchRelease NotesThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchThird Party Advisory
- PatchRelease NotesThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.11.1 (исключая)
cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*
EPSS
Процентиль: 82%
0.01633
Низкий
7.2 High
CVSS3
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-88
Связанные уязвимости
CVSS3: 7.2
debian
почти 4 года назад
The package weblate from 0 and before 4.11.1 are vulnerable to Remote ...
CVSS3: 8.8
github
почти 4 года назад
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate
EPSS
Процентиль: 82%
0.01633
Низкий
7.2 High
CVSS3
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-88