ghsa-jfgp-674x-6q4p
Vulnerability from github
Published
2024-07-01 21:02
Modified
2024-11-18 16:26
Severity ?
4.4 (Medium) - CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N
2.1 (Low) - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
2.1 (Low) - CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
Summary
Weblate vulnerable to improper sanitization of project backups
Details
Impact
Weblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file.
Patches
This issue has been addressed in Weblate 5.6.2 via https://github.com/WeblateOrg/weblate/commit/b6a7eace155fa0feaf01b4ac36165a9c5e63bfdd.
Workarounds
Do not allow project creation to untrusted users.
References
Thanks to Bryan Cahill for bringing this issue to our attention.
For more information
If you have any questions or comments about this advisory: * Open a topic in discussions * Email us at care@weblate.org
{ "affected": [ { "package": { "ecosystem": "PyPI", "name": "Weblate" }, "ranges": [ { "events": [ { "introduced": "4.14" }, { "fixed": "5.6.2" } ], "type": "ECOSYSTEM" } ] } ], "aliases": [ "CVE-2024-39303" ], "database_specific": { "cwe_ids": [ "CWE-73" ], "github_reviewed": true, "github_reviewed_at": "2024-07-01T21:02:30Z", "nvd_published_at": "2024-07-01T19:15:05Z", "severity": "LOW" }, "details": "### Impact\nWeblate didn\u0027t correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to\nfiles on the server using a crafted ZIP file.\n\n### Patches\nThis issue has been addressed in Weblate 5.6.2 via https://github.com/WeblateOrg/weblate/commit/b6a7eace155fa0feaf01b4ac36165a9c5e63bfdd.\n\n### Workarounds\nDo not allow project creation to untrusted users.\n\n### References\nThanks to Bryan Cahill for bringing this issue to our attention.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open a topic in [discussions](https://github.com/WeblateOrg/weblate/discussions)\n* Email us at [care@weblate.org](mailto:care@weblate.org)\n", "id": "GHSA-jfgp-674x-6q4p", "modified": "2024-11-18T16:26:48Z", "published": "2024-07-01T21:02:30Z", "references": [ { "type": "WEB", "url": "https://github.com/WeblateOrg/weblate/security/advisories/GHSA-jfgp-674x-6q4p" }, { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-39303" }, { "type": "WEB", "url": "https://github.com/WeblateOrg/weblate/commit/b6a7eace155fa0feaf01b4ac36165a9c5e63bfdd" }, { "type": "PACKAGE", "url": "https://github.com/WeblateOrg/weblate" } ], "schema_version": "1.4.0", "severity": [ { "score": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N", "type": "CVSS_V3" }, { "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N", "type": "CVSS_V4" } ], "summary": "Weblate vulnerable to improper sanitization of project backups" }
Loading...
Loading...
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.