Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-22251

Опубликовано: 12 янв. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 5.3

Описание

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.

РелизСтатусПримечание
devel

needed

esm-apps/bionic

released

0.8-1ubuntu0.1~esm1
esm-apps/focal

released

1.2-1ubuntu0.20.04.1~esm1
esm-apps/jammy

released

1.2-1ubuntu0.22.04.1~esm1
esm-apps/noble

released

1.13-2ubuntu0.1~esm1
esm-apps/resolute

needed

jammy

needed

noble

needed

plucky

ignored

end of life, was needs-triage
questing

released

1.15-2ubuntu0.1

Показывать по

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
7 месяцев назад

wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.

CVSS3: 5.3
debian
7 месяцев назад

wlc is a Weblate command-line client using Weblate's REST API. Prior t ...

CVSS3: 5.3
github
7 месяцев назад

Weblate wlc has insecure API key configuration

5.3 Medium

CVSS3