weblate@5.15 vulnerabilities

A web-based continuous localization system with tight version control integration

  • latest version

    5.15.1

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    26 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the weblate package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Arbitrary File Upload

    Affected versions of this package are vulnerable to Arbitrary File Upload via the GIT_SSH_COMMAND command. An attacker can execute arbitrary code and gain full control over the system by remotely overwriting configuration files.

    How to fix Arbitrary File Upload?

    Upgrade Weblate to version 5.15.1 or higher.

    [,5.15.1)
    • M
    Directory Traversal

    Affected versions of this package are vulnerable to Directory Traversal via crafted symbolic links in the repository. An attacker can access sensitive files on the server filesystem by creating and referencing symbolic links that point to arbitrary locations.

    How to fix Directory Traversal?

    Upgrade Weblate to version 5.15.1 or higher.

    [,5.15.1)